[{"data":1,"prerenderedAt":493},["ShallowReactive",2],{"navigation":3,"\u002Fmodules\u002Freauth":94,"\u002Fmodules\u002Freauth-surround":488},[4,33,52],{"title":5,"path":6,"stem":7,"children":8,"icon":32},"Getting Started","\u002Fgetting-started","1.getting-started\u002F1.index",[9,12,17,22,27],{"title":10,"path":6,"stem":7,"icon":11},"Introduction","i-lucide-house",{"title":13,"path":14,"stem":15,"icon":16},"Installation","\u002Fgetting-started\u002Finstallation","1.getting-started\u002F2.installation","i-lucide-download",{"title":18,"path":19,"stem":20,"icon":21},"Quick start","\u002Fgetting-started\u002Fquick-start","1.getting-started\u002F3.quick-start","i-lucide-play",{"title":23,"path":24,"stem":25,"icon":26},"Configuration","\u002Fgetting-started\u002Fconfiguration","1.getting-started\u002F4.configuration","i-lucide-settings",{"title":28,"path":29,"stem":30,"icon":31},"Production","\u002Fgetting-started\u002Fproduction","1.getting-started\u002F5.production","i-lucide-shield-check","i-lucide-rocket",{"title":34,"path":35,"stem":36,"children":37,"icon":51},"Composable Endpoints","\u002Fcomposables","2.composables\u002F1.index",[38,41,46],{"title":39,"path":35,"stem":36,"icon":40},"Overview","i-lucide-layout-grid",{"title":42,"path":43,"stem":44,"icon":45},"Requirements","\u002Fcomposables\u002Frequirements","2.composables\u002F2.requirements","i-lucide-list-checks",{"title":47,"path":48,"stem":49,"icon":50},"Recipes","\u002Fcomposables\u002Frecipes","2.composables\u002F3.recipes","i-lucide-book-marked","i-lucide-blocks",{"title":53,"icon":54,"path":55,"stem":56,"children":57,"page":93},"Modules","i-lucide-package","\u002Fmodules","3.modules",[58,63,68,73,78,83,88],{"title":59,"path":60,"stem":61,"icon":62},"Identity management","\u002Fmodules\u002Fidentity-management","3.modules\u002F1.identity-management","i-lucide-user-cog",{"title":64,"path":65,"stem":66,"icon":67},"Cookie auth","\u002Fmodules\u002Fcookie-auth","3.modules\u002F2.cookie-auth","i-lucide-cookie",{"title":69,"path":70,"stem":71,"icon":72},"Bearer auth","\u002Fmodules\u002Fbearer-auth","3.modules\u002F3.bearer-auth","i-lucide-key",{"title":74,"path":75,"stem":76,"icon":77},"JWT","\u002Fmodules\u002Fjwt","3.modules\u002F4.jwt","i-lucide-fingerprint",{"title":79,"path":80,"stem":81,"icon":82},"Passkeys","\u002Fmodules\u002Fpasskeys","3.modules\u002F5.passkeys","i-lucide-scan-face",{"title":84,"path":85,"stem":86,"icon":87},"ReAuth","\u002Fmodules\u002Freauth","3.modules\u002F6.reauth","i-lucide-shield-alert",{"title":89,"path":90,"stem":91,"icon":92},"External OAuth","\u002Fmodules\u002Fexternal-oauth","3.modules\u002F7.external-oauth","i-lucide-log-in",false,{"id":95,"title":84,"body":96,"description":481,"extension":482,"links":483,"meta":484,"navigation":485,"path":85,"seo":486,"stem":86,"__hash__":487},"docs\u002F3.modules\u002F6.reauth.md",{"type":97,"value":98,"toc":471},"minimark",[99,107,112,183,187,194,255,260,268,293,299,303,403,407,430,434,448,452,467],[100,101,102,103,106],"p",{},"ReAuth (step-up) confirms the user's identity before sensitive mutations. It is included when you map ",[104,105,59],"a",{"href":60}," (with antiforgery in the management map).",[108,109,111],"h2",{"id":110},"schemes-and-header","Schemes and header",[113,114,115,128],"table",{},[116,117,118],"thead",{},[119,120,121,125],"tr",{},[122,123,124],"th",{},"Piece",[122,126,127],{},"Value",[129,130,131,144,154,168],"tbody",{},[119,132,133,137],{},[134,135,136],"td",{},"Cookie scheme",[134,138,139,143],{},[140,141,142],"code",{},"AuthEndpoints.ReAuth"," (5 minutes)",[119,145,146,149],{},[134,147,148],{},"Bearer scheme",[134,150,151],{},[140,152,153],{},"AuthEndpoints.ReAuth.Bearer",[119,155,156,159],{},[134,157,158],{},"Header",[134,160,161,164,165],{},[140,162,163],{},"X-AuthEndpoints-Reauth"," with ",[140,166,167],{},"reauthToken",[119,169,170,173],{},[134,171,172],{},"Policy",[134,174,175,178,179,182],{},[140,176,177],{},"ReAuthPolicy"," (claim ",[140,180,181],{},"Reauth=true",")",[108,184,186],{"id":185},"routes","Routes",[100,188,189,190,193],{},"Mapped with management (facade under ",[140,191,192],{},"\u002Fidentity","):",[113,195,196,209],{},[116,197,198],{},[119,199,200,203,206],{},[122,201,202],{},"Method",[122,204,205],{},"Path",[122,207,208],{},"Notes",[129,210,211,226,241],{},[119,212,213,218,223],{},[134,214,215],{},[140,216,217],{},"GET",[134,219,220],{},[140,221,222],{},"\u002Fmanage\u002FauthMethods",[134,224,225],{},"Available step-up methods",[119,227,228,233,238],{},[134,229,230],{},[140,231,232],{},"POST",[134,234,235],{},[140,236,237],{},"\u002FconfirmIdentity",[134,239,240],{},"Exactly one proof; CSRF when mapped via management",[119,242,243,247,252],{},[134,244,245],{},[140,246,232],{},[134,248,249],{},[140,250,251],{},"\u002FconfirmIdentity\u002FpasskeyOptions",[134,253,254],{},"WebAuthn options for passkey step-up",[256,257,259],"h3",{"id":258},"confirmidentity-proof","ConfirmIdentity proof",[100,261,262,263,267],{},"Provide ",[264,265,266],"strong",{},"exactly one"," of:",[269,270,271,277,282,287],"ul",{},[272,273,274],"li",{},[140,275,276],{},"password",[272,278,279],{},[140,280,281],{},"twoFactorCode",[272,283,284],{},[140,285,286],{},"twoFactorRecoveryCode",[272,288,289,292],{},[140,290,291],{},"credentialJson"," (passkey assertion)",[100,294,295,296,298],{},"On success: ReAuth cookie for browser clients; ",[140,297,167],{}," for API clients using the header.",[108,300,302],{"id":301},"protecting-host-endpoints","Protecting host endpoints",[304,305,310],"pre",{"className":306,"code":307,"language":308,"meta":309,"style":309},"language-cs shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","builder.Services.AddCookieAuthEndpoints(); \u002F\u002F or AddBearerAuthEndpoints — registers ReAuth schemes\n\napp.MapPost(\"\u002Fbilling\u002Fupdate\", handler)\n    .RequireAuthorization()\n    .RequireReauth();\n","cs","",[140,311,312,341,348,380,392],{"__ignoreMap":309},[313,314,317,321,325,328,330,334,337],"span",{"class":315,"line":316},"line",1,[313,318,320],{"class":319},"sTEyZ","builder",[313,322,324],{"class":323},"sMK4o",".",[313,326,327],{"class":319},"Services",[313,329,324],{"class":323},[313,331,333],{"class":332},"s2Zo4","AddCookieAuthEndpoints",[313,335,336],{"class":323},"();",[313,338,340],{"class":339},"sHwdD"," \u002F\u002F or AddBearerAuthEndpoints — registers ReAuth schemes\n",[313,342,344],{"class":315,"line":343},2,[313,345,347],{"emptyLinePlaceholder":346},true,"\n",[313,349,351,354,356,359,362,365,369,371,374,377],{"class":315,"line":350},3,[313,352,353],{"class":319},"app",[313,355,324],{"class":323},[313,357,358],{"class":332},"MapPost",[313,360,361],{"class":323},"(",[313,363,364],{"class":323},"\"",[313,366,368],{"class":367},"sfazB","\u002Fbilling\u002Fupdate",[313,370,364],{"class":323},[313,372,373],{"class":323},",",[313,375,376],{"class":319}," handler",[313,378,379],{"class":323},")\n",[313,381,383,386,389],{"class":315,"line":382},4,[313,384,385],{"class":323},"    .",[313,387,388],{"class":332},"RequireAuthorization",[313,390,391],{"class":323},"()\n",[313,393,395,397,400],{"class":315,"line":394},5,[313,396,385],{"class":323},[313,398,399],{"class":332},"RequireReauth",[313,401,402],{"class":323},"();\n",[108,404,406],{"id":405},"typical-client-flow","Typical client flow",[408,409,410,415,420,425],"ol",{},[272,411,412],{},[140,413,414],{},"GET \u002Fidentity\u002Fmanage\u002FauthMethods",[272,416,417,418,182],{},"Collect proof (password, 2FA, or passkey via ",[140,419,251],{},[272,421,422],{},[140,423,424],{},"POST \u002Fidentity\u002FconfirmIdentity",[272,426,427,428],{},"Retry the sensitive action with ReAuth cookie and\u002For ",[140,429,163],{},[108,431,433],{"id":432},"where-reauth-is-required","Where ReAuth is required",[269,435,436,439,442],{},[272,437,438],{},"Manage 2FA \u002F info mutations",[272,440,441],{},"Passkey add, rename, delete, and creation options",[272,443,444,445],{},"Any host endpoint with ",[140,446,447],{},".RequireReauth()",[108,449,451],{"id":450},"related","Related",[269,453,454,458,462],{},[272,455,456],{},[104,457,59],{"href":60},[272,459,460],{},[104,461,79],{"href":80},[272,463,464],{},[104,465,466],{"href":43},"Composable requirements",[468,469,470],"style",{},"html pre.shiki code .sTEyZ, html code.shiki .sTEyZ{--shiki-light:#90A4AE;--shiki-default:#EEFFFF;--shiki-dark:#BABED8}html pre.shiki code .sMK4o, html code.shiki .sMK4o{--shiki-light:#39ADB5;--shiki-default:#89DDFF;--shiki-dark:#89DDFF}html pre.shiki code .s2Zo4, html code.shiki .s2Zo4{--shiki-light:#6182B8;--shiki-default:#82AAFF;--shiki-dark:#82AAFF}html pre.shiki code .sHwdD, html code.shiki .sHwdD{--shiki-light:#90A4AE;--shiki-light-font-style:italic;--shiki-default:#546E7A;--shiki-default-font-style:italic;--shiki-dark:#676E95;--shiki-dark-font-style:italic}html pre.shiki code .sfazB, html code.shiki .sfazB{--shiki-light:#91B859;--shiki-default:#C3E88D;--shiki-dark:#C3E88D}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":309,"searchDepth":316,"depth":343,"links":472},[473,474,477,478,479,480],{"id":110,"depth":343,"text":111},{"id":185,"depth":343,"text":186,"children":475},[476],{"id":258,"depth":350,"text":259},{"id":301,"depth":343,"text":302},{"id":405,"depth":343,"text":406},{"id":432,"depth":343,"text":433},{"id":450,"depth":343,"text":451},"Step-up reauthentication for sensitive manage and passkey actions.","md",null,{},{"icon":87},{"title":84,"description":481},"OPVvkG-MOrqucqR6NfQIhRlGbVqPdjSe4TE4SEqIqxs",[489,491],{"title":79,"path":80,"stem":81,"description":490,"icon":82,"children":-1},"WebAuthn passwordless register\u002Flogin and credential management endpoints.",{"title":89,"path":90,"stem":91,"description":492,"icon":92,"children":-1},"Separate preview package for GitHub and Google OAuth login with Identity cookie or JWT completion.",1785399440326]