AuthorizationContextExtensions Class
Provides extension methods for working with AuthorizationContext objects, facilitating the conversion between authorization contexts and JWT claims.
public static class AuthorizationContextExtensionsInheritance System.Object → AuthorizationContextExtensions
Methods
AuthorizationContextExtensions.ApplyTo(this AuthorizationContext, JsonWebTokenPayload) Method
Applies the information from an AuthorizationContext to a JsonWebTokenPayload, converting the context into JWT claims.
public static void ApplyTo(this Abblix.Oidc.Server.Common.AuthorizationContext context, Abblix.Jwt.JsonWebTokenPayload payload);Parameters
context AuthorizationContext
The AuthorizationContext containing authorization details.
payload JsonWebTokenPayload
The JWT payload where the authorization context information will be applied as claims.
Remarks
This method is useful for embedding authorization details directly into a JWT, allowing for efficient transfer and validation of authorization information.
AuthorizationContextExtensions.ToAuthorizationContext(this JsonWebTokenPayload) Method
Creates an AuthorizationContext from a JsonWebTokenPayload, converting JWT claims back into an authorization context.
public static Abblix.Oidc.Server.Common.AuthorizationContext ToAuthorizationContext(this Abblix.Jwt.JsonWebTokenPayload payload);Parameters
payload JsonWebTokenPayload
The JWT payload containing claims that represent an authorization context.
Returns
AuthorizationContext
An instance of AuthorizationContext populated with information derived from
the JWT claims.
Remarks
This method facilitates the extraction of authorization details from JWT claims, reconstructing an AuthorizationContext for further processing or validation.
AuthorizationContextExtensions.WithDefaultResource(this AuthorizationContext, Uri) Method
Names the given resource as the audience when the context names none, so a token says which party is meant to consume it rather than which one asked for it.
public static Abblix.Oidc.Server.Common.AuthorizationContext WithDefaultResource(this Abblix.Oidc.Server.Common.AuthorizationContext context, System.Uri? defaultResource);Parameters
context AuthorizationContext
The authorization context to complete.
defaultResource System.Uri
The resource to fall back on, or null to leave the context alone.
Returns
AuthorizationContext
The context, with the default resource applied where it was needed.
Remarks
RFC 9068 Section 3: "If the request does not include a `resource` parameter, the authorization server MUST use a default resource indicator in the `aud` claim." With no default supplied the context is returned untouched and the audience later falls back to the issuer (see ApplyTo(this AuthorizationContext, JsonWebTokenPayload)) - the behaviour changes only where a host states the default, because that value is read by every resource server in the deployment. A context that already names a resource or an audience is returned unchanged: it says who the token is for, and this only fills a gap.