Releases: marioarce/PowerCSharp
Release list
PowerCSharo - Sanitization Feature v1.0.0 — Log Injection, Path Traversal, Sensitive Data & Regex Injection Protection
Overview
This release introduces the Sanitization pluggable feature family: a framework-agnostic sanitization
engine plus Features Framework wiring, covering four security concerns in untrusted input handling:
- Log injection (CWE-117)
- File-path traversal (CWE-22)
- Sensitive-data exposure (CWE-200)
- Regex-injection / ReDoS (CWE-400 / CWE-730)
The engine was migrated and de-branded from an internal reference implementation, then refactored
from a single 1800+ line class into concern-based files for maintainability. This is a new,
independently versioned package family (PowerCSharpFeatureSanitizationVersion), alongside the
existing Core, Compatibility, Features, and Cache families.
No breaking changes. Nothing in this release modifies existing shipped packages' public APIs.
New Packages
PowerCSharp.Feature.Sanitization.Abstractions v1.0.0
Framework-agnostic engine, contracts, and safe-off NoOp implementation. Targets netstandard2.0
and net8.0, so it can be used standalone with no dependency injection or configuration required
— including from .NET Framework consumers via a hot-path logging call site.
SanitizationEngine— static engine, split by concern:SanitizationEngine.LogInjection.cs— control-character removal/replacement/encoding strategiesSanitizationEngine.FilePath.cs— allowlist validation (recommended) and legacy pattern-stripping modesSanitizationEngine.SensitiveData.cs— pattern-based detection and masking of tokens, secrets, credentials, URLs, and file pathsSanitizationEngine.RegexInjection.cs— pattern-safety validation: length, compile-with-timeout, complexity scoring, and configurable rejection of catastrophic-backtracking shapes
SanitizationExtensions— string extension methods (SanitizeForLog,SanitizeForFilePath,SanitizeForSensitiveData,SanitizeForRegexInjection,*WithDetailsvariants,Mask)SanitizationSettings— full configurable surface, secure defaults throughoutSanitizationResult/SensitiveDataResult— immutable result types withUnchanged/Modified/RejectedfactoriesISanitizationService/ISanitizationSettingsProvider— DI-facing contractsNoOpSanitizationService— safe-off floor
PowerCSharp.Feature.Sanitization v1.0.0
Features Framework module, options, and DI/ASP.NET Core wiring.
SanitizationFeatureModule— auto-discoverable; registers the real service when enabled, NoOp when disabled. Unlike the Cache family, there is no separate provider package, so this module decides active-vs-NoOp directly.SanitizationFeatureOptions— bound fromPowerFeatures:Sanitization, mirroring the full settings surfaceSanitizationService/SanitizationSettingsProvider— DI implementation, bridging bound options into the engineAddSanitizationFeature()— explicit registration extensionConfigureSanitizationEngine()— bridges DI-resolved settings into the static engine, so extension-method call sites reflect host configuration too
Testing
New PowerCSharp.Feature.Sanitization.Tests project (xUnit) covering:
- Log injection: control-character strategies, tab preservation, disabled-flag passthrough, length limiting
- File-path traversal: strict allowlist validation (traversal, absolute paths, reserved device names, extension/base-directory allowlists), legacy pattern-stripping mode, correlation-id sanitization
- Sensitive-data masking: key-value pairs, bearer tokens, API keys, file paths, strictness levels, custom mask characters
- Regex injection: safe-pattern acceptance, syntax rejection, nested-quantifier rejection (and explicit opt-in), pattern-length limits, individually disallowed constructs
- Extension methods and result-type value equality
- Feature DI wiring: explicit registration, options binding, NoOp behavior, static-engine bridging
Fixed
Found while writing the test suite: MaskKeyBasedValues's handling of the generic
password/token/secret/etc. key-value pattern referenced a regex capture group that didn't
exist, which always evaluated to an empty mask and silently left the raw secret value in the
sanitized output (with the key name dropped). The same defect exists in the original reference
implementation this was migrated from. Fixed by reconstructing the key prefix the same way the
other key-based heuristics in the same method already do — masking now works correctly for this
pattern class.
Sample Application
WebSample now references the Features Framework for the first time and demonstrates both shipped
feature families:
GET /demo/cache— cache miss followed by a set/hit round-trip via the BitFaster providerGET /demo/sanitization— all four sanitization concerns against representative malicious input
Installation
dotnet add package PowerCSharp.Feature.Sanitization.Abstractions
dotnet add package PowerCSharp.Feature.SanitizationConfiguration
{
"PowerFeatures": {
"Sanitization": {
"Enabled": true,
"EnableLogSanitization": true,
"EnableFilePathSanitization": true,
"EnableSensitiveDataDetection": true,
"EnableRegexSanitization": true
}
}
}Documentation
- Package readmes:
PowerCSharp.Feature.Sanitization.Abstractions,PowerCSharp.Feature.Sanitization - API reference:
docs/PowerCSharp.Feature.Sanitization.md - CHANGELOG: see the
Sanitization 1.0.0section
Versioning
This release establishes PowerCSharpFeatureSanitizationVersion (starting at 1.0.0) as a new
independent version family, alongside a sanitization package-family option in the release
workflow. Future Sanitization-only changes will bump this family independently of Core, Features,
and Cache.
PowerCSharp v2.0.2 — Features Framework & Cache Family
This is the v2.0.x line's headline release. It introduces the brand-new PowerCSharp Features architecture — a production-grade, modular, flag-driven system that lets developers compose, toggle, and ship capabilities independently, without coupling package adoption to application deployment.
What Is the Features Framework?
The Features system is a first-class extension point for the PowerCSharp ecosystem. It defines two tiers of capability:
| Tier | Name | Shipped in | Gate |
|---|---|---|---|
| Group 1 | Built-in Features | PowerCSharp.BuiltInFeatures |
Runtime flag only |
| Group 2 | Pluggable Features | Standalone packages (PowerCSharp.Feature.*) |
Package reference + runtime flag |
Both tiers are self-contained, independently versioned, and share a common contract surface (PowerCSharp.Features.Abstractions) that any developer or company can implement to build their own feature.
📦 New Packages in v2.0.x
Features Framework Trio — v1.0.1
| Package | Role |
|---|---|
PowerCSharp.Features.Abstractions |
Contracts only: IFeatureModule, IFeatureFlagProvider, FeatureOptionsBase, FeatureDescriptor. Zero third-party deps. netstandard2.0 + net8.0. |
PowerCSharp.Features |
The engine: module auto-discovery, composite flag resolver, DI orchestration, feature registry, opt-in diagnostics endpoint. |
PowerCSharp.BuiltInFeatures |
Bundle of runtime-toggled ASP.NET Core capabilities. First built-in: CORS. |
Cache Feature Family — v1.3.1
| Package | Role |
|---|---|
PowerCSharp.Feature.Cache.Abstractions |
Framework-agnostic cache contracts (ICacheService, IDiskCacheService, CacheResult<T>, CacheMetadata). NoOp safe-off floor. netstandard2.0 + net8.0. |
PowerCSharp.Feature.Cache |
Cache feature module, CacheFeatureOptions, AddCacheFeature(). |
PowerCSharp.Feature.Cache.BitFaster |
High-performance in-memory LRU cache backed by BitFaster.Caching. Stampede protection. |
PowerCSharp.Feature.Cache.Disk |
Disk-backed LRU with atomic writes, cross-process file locks, and background cleanup. |
⚡ Quick Start
Features Framework
dotnet add package PowerCSharp.Features.Abstractions
dotnet add package PowerCSharp.Features
dotnet add package PowerCSharp.BuiltInFeatures// Program.cs
builder.Services.AddPowerFeatures(builder.Configuration, options =>
{
options.AddBuiltInFeatures(); // CORS and other built-ins
options.ScanAssemblies(typeof(CacheFeatureModule).Assembly);
options.Override("Cache", true); // code-level override
options.EnableDiagnosticsEndpoint(); // GET /power-features
});
var app = builder.Build();
app.UsePowerFeatures();// appsettings.json
{
"PowerFeatures": {
"Cors": { "Enabled": true, "AllowedOrigins": ["https://example.com"] },
"Cache": { "Enabled": true, "Provider": "BitFaster", "Capacity": 5000 }
}
}Cache Feature
dotnet add package PowerCSharp.Feature.Cache
dotnet add package PowerCSharp.Feature.Cache.BitFaster # or .Diskvar cache = app.Services.GetRequiredService<ICacheService>();
var result = await cache.GetAsync<MyData>("key");
if (!result.Hit)
{
var data = await FetchFromSourceAsync();
await cache.SetAsync("key", data, TimeSpan.FromMinutes(10));
}🏗️ Architecture Highlights
Flag Resolution Chain (highest precedence first)
Code override → Custom IFeatureFlagProvider → Environment variables → appsettings → Feature default
Environment variable convention:
POWERFEATURES__CACHE__ENABLED=true
POWERFEATURES__CORS__ENABLED=false
Two-Layer Gating (Pluggable Features)
| Scenario | Result |
|---|---|
| No package reference | Feature doesn't exist — zero code, zero deps |
| Package referenced, flag off | NoOp registered — dependents always resolve safely |
| Package referenced, flag on | Active provider registered — full functionality |
Diagnostics Endpoint
When enabled, GET /power-features returns the live feature matrix:
[
{ "Key": "Cache", "Tier": "Pluggable", "Enabled": true, "Source": "Configuration", "Version": "1.3.1" },
{ "Key": "Cors", "Tier": "BuiltIn", "Enabled": true, "Source": "Configuration", "Version": "1.0.1" }
]🔧 Also in v2.0.x
- EditorConfig — comprehensive coding standards (member ordering, braces, nullable) applied across the full codebase
DirectoryExtensions—TrySafeDeleteand safe directory-manipulation helpers- CI/CD —
update-versionworkflow now supports independent version bumping per package family (core/features/cache) viaworkflow_dispatch - Code quality — all
Console.WriteLinedebug artifacts removed from production library code; startup logging viaILoggerinUsePowerFeatures
📚 Documentation
| Document | Description |
|---|---|
| Features Architecture | System design, two tiers, dependency topology |
| Features Engine API | AddPowerFeatures, UsePowerFeatures, PowerFeaturesOptions, registry |
| BuiltInFeatures API | CORS reference, replace-a-builtin pattern, roadmap |
| Cache Family API | Full Cache family reference, ICacheService, providers |
| Authoring Guide | Step-by-step guide to building a new Feature |
| Flag Reference | Flag schema, provider precedence, environment conventions |
🚀 Installation — Full Suite
# Core libraries (v2.0.2)
dotnet add package PowerCSharp.Core
dotnet add package PowerCSharp.Extensions
dotnet add package PowerCSharp.Extensions.AspNetCore
dotnet add package PowerCSharp.Utilities
dotnet add package PowerCSharp.Helpers
# Features framework (v1.0.1)
dotnet add package PowerCSharp.Features.Abstractions
dotnet add package PowerCSharp.Features
dotnet add package PowerCSharp.BuiltInFeatures
# Cache feature (v1.3.1) — pick a provider
dotnet add package PowerCSharp.Feature.Cache
dotnet add package PowerCSharp.Feature.Cache.BitFaster # in-memory LRU
dotnet add package PowerCSharp.Feature.Cache.Disk # disk-backed LRU🤝 Build Your Own Feature
The contract is open. Any developer or company can:
- Reference
PowerCSharp.Features.Abstractions - Implement
IFeatureModule - Optionally implement
IFeatureFlagProviderfor custom flag sources (Azure App Config, AWS SSM, database, etc.) - Register via
options.ScanAssemblies(...)oroptions.AddModule(...)
The engine handles discovery, flag resolution, DI orchestration, startup logging, and diagnostics — your module focuses only on its own capability.
📊 Package Statistics
🔮 Roadmap — v2.1.x
PowerCSharp.Feature.Cache.Memory— nativeIMemoryCacheprovider- Built-in Features:
CorrelationId,SecurityHeaders,ExceptionHandling PowerCSharp.Feature.Observability— OpenTelemetry integration- Hotfix branch CI/CD support
🙏 Thank You
Built by Mario Arce — Software Architect with 20+ years of enterprise C# experience. This release is the foundation for a modular, composable C# ecosystem that grows with your project, not against it.
⭐ Star the repo — it helps more developers discover the library.
🐛 Report Issues
💬 GitHub Discussions
PowerCSharp v2.0.2 · PowerCSharp.Features v1.0.1 · PowerCSharp.Feature.Cache v1.3.1
#PowerCSharp #CSharp #DotNet #OpenSource #NuGet #FeatureFlags #Architecture
PowerCSharp v1.0.0 - Production Ready!
PowerCSharp v1.0.0 Release Notes
Release Date: June 8, 2026
🎉 Major Release - Production Ready
PowerCSharp v1.0.0 marks the first stable production release of the comprehensive C# extension methods and utilities library. This release represents months of development, testing, and refinement to deliver a library ready for enterprise use.
📋 Executive Summary
PowerCSharp v1.0.0 provides:
- Production Stability: All APIs finalized and tested for production workloads
- Complete Feature Set: 6 focused packages with comprehensive functionality
- Modern .NET Support: Full .NET 8.0 optimization with backward compatibility
- Professional Quality: Enterprise-grade documentation, testing, and CI/CD
- Semantic Versioning: Proper version management for long-term maintenance
🚀 What's New in v1.0.0
Production Readiness
- ✅ API Finalization: All extension methods, utilities, and helpers are now stable
- ✅ Comprehensive Testing: Extensive test coverage with edge case validation
- ✅ Performance Optimization: Optimized for .NET 8.0 with reduced allocations
- ✅ Security Review: Complete security audit with no critical issues
- ✅ Documentation Overhaul: Complete API reference and usage guides
Package Enhancements
- ✅ NuGet Package Icons: Professional 128x128 icons for all packages
- ✅ Metadata Consistency: Standardized package information across all packages
- ✅ Semantic Versioning: Proper v1.0.0 versioning with breaking change policy
- ✅ Dependency Management: Updated to latest stable dependencies
Developer Experience
- ✅ Enhanced README: Comprehensive getting started guide and examples
- ✅ Detailed Changelog: Complete version history and migration notes
- ✅ API Documentation: Complete reference for all packages
- ✅ Sample Applications: Working code examples and demonstrations
📦 Package Overview
Core Packages
PowerCSharp.Core v1.0.0
- Purpose: Foundation library with centralized interfaces and models
- Key Features: Base classes, interfaces, and architectural components
- Target Frameworks: .NET 8.0, .NET Standard 2.0
- Dependencies: None (dependency-free core)
PowerCSharp.Extensions v1.0.0
- Purpose: Cross-platform extension methods for common .NET types
- Key Features: String, DateTime, Collection, HTTP, LINQ, JSON, XML, Object, Type, and Stream extensions
- Target Frameworks: .NET 8.0, .NET Standard 2.0
- Dependencies: PowerCSharp.Core, System.Linq.Dynamic.Core, System.Text.Json, Ben.Demystifier
PowerCSharp.Extensions.AspNetCore v1.0.0
- Purpose: ASP.NET Core specific extensions and utilities
- Key Features: HTTP utilities, configuration extensions, web-specific helpers
- Target Frameworks: .NET 8.0
- Dependencies: PowerCSharp.Core, Microsoft.AspNetCore.WebUtilities, Microsoft.Extensions.Configuration packages
PowerCSharp.Utilities v1.0.0
- Purpose: Utility classes for common programming tasks
- Key Features: Validation, file operations, mathematical utilities
- Target Frameworks: .NET 8.0, .NET Standard 2.0
- Dependencies: PowerCSharp.Core
PowerCSharp.Helpers v1.0.0
- Purpose: Specialized helper classes for advanced operations
- Key Features: JSON helpers, cryptography, environment utilities
- Target Frameworks: .NET 8.0, .NET Standard 2.0
- Dependencies: PowerCSharp.Core, System.Text.Json
PowerCSharp.Compatibility v1.0.0
- Purpose: .NET Framework compatibility layer
- Key Features: Legacy framework support with System.Web dependencies
- Target Frameworks: .NET 4.6.2, .NET 4.7.2, .NET 4.8
- Dependencies: System.Text.Json, System.Net.Http, Microsoft.CSharp
🔄 Migration Guide
From v0.x.x to v1.0.0
Good News: No breaking changes! All APIs remain compatible.
Required Actions
-
Update Package References:
<PackageReference Include="PowerCSharp.Core" Version="1.0.0" /> <PackageReference Include="PowerCSharp.Extensions" Version="1.0.0" /> <!-- etc. -->
-
Verify Target Frameworks:
- Modern .NET: Continue using .NET 8.0 or .NET Standard 2.0
- .NET Framework: Continue using PowerCSharp.Compatibility
-
Review New Features:
- Check new extension methods added in v1.0.0
- Review updated documentation for best practices
No Code Changes Required
- All existing code will continue to work without modification
- APIs remain stable and follow semantic versioning
- Performance improvements are transparent
🛠️ Installation
Individual Packages
dotnet add package PowerCSharp.Core
dotnet add package PowerCSharp.Extensions
dotnet add package PowerCSharp.Extensions.AspNetCore
dotnet add package PowerCSharp.Utilities
dotnet add package PowerCSharp.Helpers
dotnet add package PowerCSharp.CompatibilityComplete Suite
dotnet add package PowerCSharp.Core
dotnet add package PowerCSharp.Extensions
dotnet add package PowerCSharp.Extensions.AspNetCore
dotnet add package PowerCSharp.Utilities
dotnet add package PowerCSharp.Helpers
dotnet add package PowerCSharp.Compatibility📊 Statistics
Code Metrics
- Total Lines of Code: ~15,000+ lines
- Extension Methods: 100+ methods across 20+ extension classes
- Utility Classes: 15+ helper and utility classes
- Test Coverage: 90%+ coverage with 200+ unit tests
- Target Frameworks: 6 framework combinations
- Packages: 6 focused NuGet packages
Quality Metrics
- Build Status: ✅ All builds passing
- Code Quality: ✅ A+ grade with static analysis
- Security: ✅ No critical vulnerabilities
- Documentation: ✅ 100% API coverage
- Performance: ✅ Optimized for .NET 8.0
🔧 Technical Highlights
Architecture
- Centralized Interfaces: All interfaces in PowerCSharp.Core
- Clean Separation: Proper dependency management
- Modular Design: Selective package installation
- Consistent Namespaces: Organized across the ecosystem
Performance
- Memory Optimization: Reduced allocations in hot paths
- Async Support: Full async/await pattern support
- LINQ Optimization: Efficient dynamic query processing
- Stream Performance: Optimized stream operations
Security
- Input Validation: Comprehensive parameter validation
- Path Security: Directory traversal protection
- Cryptography: Secure hashing and encryption
- Dependency Audit: All dependencies security-scanned
🐛 What's Fixed
Code Quality
- Resolved nullable reference warnings
- Improved exception handling
- Enhanced parameter validation
- Better error messages
Performance
- Optimized string operations
- Improved collection performance
- Reduced memory allocations
- Faster JSON processing
Documentation
- Complete API reference
- Comprehensive examples
- Migration guides
- Best practices documentation
🚀 Breaking Changes Policy
v1.0.0 Stability Guarantee
- API Stability: All public APIs are stable and will not change
- Semantic Versioning: Strict adherence to semantic versioning
- Backward Compatibility: Maintained for all v1.x.x releases
- Deprecation Policy: 12-month deprecation notice for breaking changes
Future Compatibility
- v1.1.x: New features, no breaking changes
- v1.2.x: New features, no breaking changes
- v2.0.0: Breaking changes (planned for .NET 9.0 transition)
🎯 Support and Maintenance
Getting Help
- Documentation: Complete API Reference
- Issues: GitHub Issues
- Discussions: GitHub Discussions
- Examples: Sample Applications
Maintenance
- Regular Updates: Monthly patch releases as needed
- Security Updates: Immediate patches for critical issues
- Feature Requests: Community-driven feature development
- Long-term Support: Commitment to v1.x.x stability
🏆 Acknowledgments
Contributors
- Mario Arce: Lead architect and developer
- Community: Feedback, suggestions, and contributions
- Beta Testers: Production validation and feedback
Inspiration
- 20+ Years Experience: Built on real-world C# development
- Enterprise Needs: Designed for production workloads
- Community Standards: Following .NET best practices
📈 What's Next
v1.1.0 (Planned)
- Additional string manipulation methods
- Enhanced cryptographic utilities
- Performance optimizations
- More validation helpers
v1.2.0 (Planned)
- Async extension methods
- Caching utilities
- Logging helpers
- Configuration extensions
v2.0.0 (Future)
- .NET 9.0 support
- Updated API design
- Removed deprecated methods
- Enhanced performance
🔗 Links
- NuGet Gallery: https://www.nuget.org/profiles/marioarce
- GitHub Repository: https://github.com/marioarce/PowerCSharp
- Documentation: https://github.com/marioarce/PowerCSharp/docs
- Examples: https://github.com/marioarce/PowerCSharp/samples
PowerCSharp v1.0.0 - Production Ready! 🚀
Built with passion for the C# community.