AuthorizationCodeReusePreventingDecorator Class
Refuses a second redemption of an authorization code, and revokes the tokens the first one issued, in compliance with OAuth 2.0 security best practices. Two defences, split by WHEN the repeat arrives rather than by where: the claim refuses one arriving beside the first, and the issued tokens written back at the key catch one arriving after it. Both hold across processes.
public class AuthorizationCodeReusePreventingDecorator : Abblix.Oidc.Server.Endpoints.Token.Interfaces.ITokenRequestProcessorInheritance System.Object → AuthorizationCodeReusePreventingDecorator
Implements ITokenRequestProcessor
Remarks
Neither is complete on its own terms. The claim reads the value under the same hold of the gate that removes it, so on ONE node two callers cannot be handed the same grant; across processes the gate holds nothing and both can be, which is issue 435. And the write-back is what the second defence rests on, so a first redemption that ends without issuing tokens leaves nothing for it to catch. The refusal this class returns is the same string either way.
This class decorates the standard token request processing flow with additional security measures to ensure the integrity of the authorization process. It detects when an authorization code, which should only be used once, is attempted to be used multiple times. In such cases, it revokes any tokens previously issued with that code and denies the request, effectively mitigating potential security risks associated with code reuse.
Constructors
AuthorizationCodeReusePreventingDecorator(ITokenRequestProcessor, ITokenRegistry, IAuthorizationCodeService) Constructor
Refuses a second redemption of an authorization code, and revokes the tokens the first one issued, in compliance with OAuth 2.0 security best practices. Two defences, split by WHEN the repeat arrives rather than by where: the claim refuses one arriving beside the first, and the issued tokens written back at the key catch one arriving after it. Both hold across processes.
public AuthorizationCodeReusePreventingDecorator(Abblix.Oidc.Server.Endpoints.Token.Interfaces.ITokenRequestProcessor processor, Abblix.Oidc.Server.Features.Storages.ITokenRegistry tokenRegistry, Abblix.Oidc.Server.Features.Storages.IAuthorizationCodeService authorizationCodeService);Parameters
processor ITokenRequestProcessor
The underlying token request processor to be enhanced.
tokenRegistry ITokenRegistry
The registry used for managing token states and revocation.
authorizationCodeService IAuthorizationCodeService
The service responsible for managing the lifecycle of authorization codes.
Remarks
Neither is complete on its own terms. The claim reads the value under the same hold of the gate that removes it, so on ONE node two callers cannot be handed the same grant; across processes the gate holds nothing and both can be, which is issue 435. And the write-back is what the second defence rests on, so a first redemption that ends without issuing tokens leaves nothing for it to catch. The refusal this class returns is the same string either way.
This class decorates the standard token request processing flow with additional security measures to ensure the integrity of the authorization process. It detects when an authorization code, which should only be used once, is attempted to be used multiple times. In such cases, it revokes any tokens previously issued with that code and denies the request, effectively mitigating potential security risks associated with code reuse.
Methods
AuthorizationCodeReusePreventingDecorator.ProcessAsync(ValidTokenRequest) Method
Processes a valid token request, including revoking existing tokens if necessary and registering new tokens.
public System.Threading.Tasks.Task<Abblix.Utils.Result<Abblix.Oidc.Server.Endpoints.Token.Interfaces.TokenIssued,Abblix.Oidc.Server.Common.OidcError>> ProcessAsync(Abblix.Oidc.Server.Endpoints.Token.Interfaces.ValidTokenRequest request);Parameters
request ValidTokenRequest
The valid token request to process.
Implements ProcessAsync(ValidTokenRequest)
Returns
System.Threading.Tasks.Task<Abblix.Utils.Result<TokenIssued,OidcError>>
A task that returns a TokenIssued on success or an OidcError on failure.