VerifiedPrincipal
Namespace: Meshmakers.Octo.Sdk.Common.Services
The authenticated caller of a pipeline trigger, verified by the trigger's authorization (e.g. FromHttpRequest@2 bearer validation — AB#4975). Carried through ExecutePipelineOptions onto the ETL context so entity-writing nodes can act under the caller's identity (RtCreatedBy stamping, data-level permissions). Deliberately a slim value object without token material: the pipeline data root is echoed in HTTP responses and persistable, so no credential may ever travel with it.
public record VerifiedPrincipal : IEquatable<VerifiedPrincipal>
Inheritance Object → VerifiedPrincipal
Implements IEquatable<VerifiedPrincipal>
Properties
SubjectId
Subject id ("sub" claim) or null for client-credentials tokens
public string SubjectId { get; set; }
Property Value
TenantId
Tenant id claim of the caller, if present
public string TenantId { get; set; }
Property Value
Email
E-mail claim of the caller, if present
public string Email { get; set; }
Property Value
Name
Display name claim of the caller, if present
public string Name { get; set; }
Property Value
Roles
Role claims of the caller
public IReadOnlyList<string> Roles { get; set; }
Property Value
PreferredChannel
The caller's preferred outbound channel for system-initiated messages (AB#5149), read from the user's identity record by the verified-caller directory. Canonical uppercase channel names — "TEAMS" | "SIGNAL" (extensible) — propagated verbatim; null when the user has no preference or the resolution path carries none (e.g. a bearer-token caller). Routing only: synchronous replies keep using the channel the message came in on.
public string PreferredChannel { get; set; }
Property Value
Constructors
VerifiedPrincipal(String, String, String, String, IReadOnlyList<String>, String)
The authenticated caller of a pipeline trigger, verified by the trigger's authorization (e.g. FromHttpRequest@2 bearer validation — AB#4975). Carried through ExecutePipelineOptions onto the ETL context so entity-writing nodes can act under the caller's identity (RtCreatedBy stamping, data-level permissions). Deliberately a slim value object without token material: the pipeline data root is echoed in HTTP responses and persistable, so no credential may ever travel with it.
public VerifiedPrincipal(string SubjectId, string TenantId, string Email, string Name, IReadOnlyList<string> Roles, string PreferredChannel)
Parameters
SubjectId String
Subject id ("sub" claim) or null for client-credentials tokens
TenantId String
Tenant id claim of the caller, if present
Email String
E-mail claim of the caller, if present
Name String
Display name claim of the caller, if present
Roles IReadOnlyList<String>
Role claims of the caller
PreferredChannel String
The caller's preferred outbound channel for system-initiated messages (AB#5149), read from the
user's identity record by the verified-caller directory. Canonical uppercase channel names —
"TEAMS" | "SIGNAL" (extensible) — propagated verbatim; null when the user has no preference or
the resolution path carries none (e.g. a bearer-token caller). Routing only: synchronous
replies keep using the channel the message came in on.