// the find
mo-esmp/DynamicRoleBasedAuthorizationNETCore
Dynamic Role-Based Access Control for ASP.NET Core MVC and Web API
A library that lets you assign ASP.NET Core MVC/Web API authorization at runtime instead of baking role names into [Authorize] attributes — it reflects over your controllers/actions, lets an admin map roles to them through a JSON file or SQL Server store, and ships an optional pre-built UI for managing that mapping. Useful for teams building internal admin tools or CMS-style apps where non-developers need to control who can hit which endpoint without a redeploy.
Clean separation between the discovery mechanism (IMvcControllerDiscovery reflecting over [Authorize]-decorated controllers), storage (pluggable IRoleAccessStore with JSON/SQL Server implementations), and presentation (optional Mvc.Ui package) — you can swap out the storage layer without touching the core. The DisplayName attribute and SecureContentTagHelper are a nice touch for also hiding nav links and page sections a user can't act on, not just blocking the controller. Four separate NuGet packages means you only pull in what you use instead of one monolithic dependency.
Samples only go up to .NET 6/7 and the last push was November 2024, so there's no evidence it's been validated against .NET 8's or .NET 9's auth pipeline changes — worth testing before adopting on anything current. The JSON store is explicitly file-based, which means concurrent writes from multiple instances or even multiple admin tabs will race; there's no documented locking or atomic-write strategy. No mention of caching the role-access lookup, so depending on implementation this could mean a store hit (file read or DB query) on every authorized request unless you add caching yourself. There are no visible unit or integration tests in the repo tree, which is a real gap for something sitting directly in your auth path.