diff --git a/astro/src/content/docs/identityserver/samples/saml.mdx b/astro/src/content/docs/identityserver/samples/saml.mdx index 141a99175..276b27075 100644 --- a/astro/src/content/docs/identityserver/samples/saml.mdx +++ b/astro/src/content/docs/identityserver/samples/saml.mdx @@ -1,6 +1,7 @@ --- title: "SAML" description: "Samples demonstrating SAML 2.0 integration with Duende IdentityServer as an Identity Provider." +date: 2026-06-02 sidebar: order: 45 --- diff --git a/astro/src/content/docs/identityserver/samples/usermanagement.mdx b/astro/src/content/docs/identityserver/samples/usermanagement.mdx new file mode 100644 index 000000000..944cbf09d --- /dev/null +++ b/astro/src/content/docs/identityserver/samples/usermanagement.mdx @@ -0,0 +1,41 @@ +--- +title: "User Management" +description: "Sample demonstrating a complete IdentityServer v8 implementation using Duende User Management with multiple authentication methods, profile management, and ASP.NET Identity migration." +date: 2026-06-02 +sidebar: + order: 48 +--- + +import { LinkCard } from "@astrojs/starlight/components"; + +This section contains a sample demonstrating [Duende User Management](/identityserver/usermanagement/index.mdx) with IdentityServer. +User Management is a user store and authentication platform that ships as a NuGet package and replaces ASP.NET Identity for IdentityServer scenarios. + +### User Management Sample + +This sample demonstrates a full IdentityServer deployment using Duende User Management for user storage and authentication. +It covers multiple authentication methods working together in a single application, orchestrated by .NET Aspire. + +**Authentication methods demonstrated:** + +- **Email OTP**: enter email, receive a code via SMTP, verify, and sign in (unknown emails are auto-registered) +- **Password + TOTP 2FA**: email/password login with time-based one-time password as a second factor +- **Passkeys**: after first OTP login, users are prompted to register a passkey for future passwordless sign-in +- **Passkey as second factor**: after password verification, users can tap a passkey instead of entering a TOTP code +- **Google external login**: OAuth callback creates or links a local profile automatically + +**Additional features:** + +- **User profile management** using a schema-driven attribute model (extensible attributes rather than a fixed user table) +- **ASP.NET Identity migration**: the Admin Import page demonstrates bulk-importing users from an existing ASP.NET Identity database, including password hash compatibility, claims-to-attributes mapping, and deterministic subject ID generation +- **Second factor state management**: encrypted cookies coordinate the 2FA flow between password verification and TOTP/passkey completion + +The sample uses .NET Aspire to orchestrate IdentityServer, a client application, and Mailpit (for local email testing) +in a single `dotnet run` command. + + diff --git a/astro/src/content/docs/identityserver/usermanagement/import/index.mdx b/astro/src/content/docs/identityserver/usermanagement/import/index.mdx index d8c336a9c..f9ef7f4b2 100644 --- a/astro/src/content/docs/identityserver/usermanagement/import/index.mdx +++ b/astro/src/content/docs/identityserver/usermanagement/import/index.mdx @@ -158,4 +158,5 @@ The best starting point depends on where your users live today: + diff --git a/astro/src/content/docs/identityserver/usermanagement/index.mdx b/astro/src/content/docs/identityserver/usermanagement/index.mdx index 52f81fabf..a7f395c7d 100644 --- a/astro/src/content/docs/identityserver/usermanagement/index.mdx +++ b/astro/src/content/docs/identityserver/usermanagement/index.mdx @@ -79,4 +79,5 @@ See the [glossary](/general/glossary.mdx) for definitions of terms used througho +