ResponseModeValidator Class
Verifies that an explicit response_mode is compatible with the OAuth 2.0 flow
derived from response_type (OAuth 2.0 Multiple Response Types §2.1, OAuth 2.0
Form Post Response Mode). For the authorization-code flow any of query,
fragment, form_post is allowed; flows that issue tokens at the
authorization endpoint (implicit, hybrid) refuse query because credentials
must not appear in the URL query string.
After that flow-compatibility check, when the client configures an explicit
AllowedResponseModes allow-list the effective response
mode must be a member of it, letting a host pin the delivery channel and close a response-mode downgrade
(RFC 9700).
public class ResponseModeValidator : Abblix.Oidc.Server.Endpoints.Authorization.Validation.SyncAuthorizationContextValidatorBaseInheritance System.Object → SyncAuthorizationContextValidatorBase → ResponseModeValidator
Constructors
ResponseModeValidator(ILogger<ResponseModeValidator>) Constructor
Verifies that an explicit response_mode is compatible with the OAuth 2.0 flow
derived from response_type (OAuth 2.0 Multiple Response Types §2.1, OAuth 2.0
Form Post Response Mode). For the authorization-code flow any of query,
fragment, form_post is allowed; flows that issue tokens at the
authorization endpoint (implicit, hybrid) refuse query because credentials
must not appear in the URL query string.
After that flow-compatibility check, when the client configures an explicit
AllowedResponseModes allow-list the effective response
mode must be a member of it, letting a host pin the delivery channel and close a response-mode downgrade
(RFC 9700).
public ResponseModeValidator(Microsoft.Extensions.Logging.ILogger<Abblix.Oidc.Server.Endpoints.Authorization.Validation.ResponseModeValidator> logger);Parameters
logger Microsoft.Extensions.Logging.ILogger<ResponseModeValidator>