Found a small bug in the extension. The extension implies only header handling should be applied but the ApiKeyInHeaderOrQueryParamsHandler is applied
On line https://github.com/mihirdilip/aspnetcore-authentication-apikey/blob/master/src/AspNetCore.Authentication.ApiKey/ApiKeyExtensions.cs#L130 it should be ApiKeyInHeaderHandler instead of ApiKeyInHeaderOrQueryParamsHandler
public static AuthenticationBuilder AddApiKeyInHeader<TApiKeyProvider>(this AuthenticationBuilder builder, string authenticationScheme, string displayName, Action<ApiKeyOptions> configureOptions) where TApiKeyProvider : class, IApiKeyProvider
=> builder.AddApiKey<TApiKeyProvider, ApiKeyInHeaderOrQueryParamsHandler>(authenticationScheme, displayName, configureOptions);
Found a small bug in the extension. The extension implies only header handling should be applied but the ApiKeyInHeaderOrQueryParamsHandler is applied
On line https://github.com/mihirdilip/aspnetcore-authentication-apikey/blob/master/src/AspNetCore.Authentication.ApiKey/ApiKeyExtensions.cs#L130 it should be
ApiKeyInHeaderHandlerinstead ofApiKeyInHeaderOrQueryParamsHandler