BackChannelAuthenticationGrantHandler Class
Handles the authorization process for backchannel authentication requests under the Client-Initiated Backchannel Authentication (CIBA) grant type. This handler validates the token request based on the backchannel authentication flow, ensuring that the client is authorized and that the user has been authenticated before tokens are issued. Supports both short-polling (immediate response) and long-polling (holds connection until auth completes).
public class BackChannelAuthenticationGrantHandler : Abblix.Oidc.Server.Endpoints.Token.Grants.IAuthorizationGrantHandler, Abblix.Oidc.Server.Common.Interfaces.IGrantTypeInformerInheritance System.Object → BackChannelAuthenticationGrantHandler
Implements IAuthorizationGrantHandler, IGrantTypeInformer
Constructors
BackChannelAuthenticationGrantHandler(ILogger<BackChannelAuthenticationGrantHandler>, IBackChannelRequestStorage, IAuthorizationDetailsPolicy, TimeProvider, IOptions<OidcOptions>, IServiceProvider, ISubjectTypeConverter, IBackChannelLongPollingService) Constructor
Handles the authorization process for backchannel authentication requests under the Client-Initiated Backchannel Authentication (CIBA) grant type. This handler validates the token request based on the backchannel authentication flow, ensuring that the client is authorized and that the user has been authenticated before tokens are issued. Supports both short-polling (immediate response) and long-polling (holds connection until auth completes).
public BackChannelAuthenticationGrantHandler(Microsoft.Extensions.Logging.ILogger<Abblix.Oidc.Server.Endpoints.Token.Grants.BackChannelAuthenticationGrantHandler> logger, Abblix.Oidc.Server.Features.BackChannelAuthentication.Interfaces.IBackChannelRequestStorage storage, Abblix.Oidc.Server.Features.RichAuthorizationRequests.IAuthorizationDetailsPolicy authorizationDetailsPolicy, System.TimeProvider timeProvider, Microsoft.Extensions.Options.IOptions<Abblix.Oidc.Server.Common.Configuration.OidcOptions> options, System.IServiceProvider serviceProvider, Abblix.Oidc.Server.Features.PairwiseIdentifiers.ISubjectTypeConverter subjectTypeConverter, Abblix.Oidc.Server.Features.BackChannelAuthentication.Interfaces.IBackChannelLongPollingService? statusNotifier=null);Parameters
logger Microsoft.Extensions.Logging.ILogger<BackChannelAuthenticationGrantHandler>
Records a refusal the client is deliberately told nothing specific about.
storage IBackChannelRequestStorage
Service for storing and retrieving backchannel authentication requests.
authorizationDetailsPolicy IAuthorizationDetailsPolicy
Asks the per-type validators whether the grant's authorization_details are still acceptable, which is the only comparison that can see inside an entry.
timeProvider System.TimeProvider
Provides access to the current time.
options Microsoft.Extensions.Options.IOptions<OidcOptions>
Configuration options for backchannel authentication including long-polling settings.
serviceProvider System.IServiceProvider
Service provider for resolving mode-specific grant processors.
subjectTypeConverter ISubjectTypeConverter
Seals the authenticated session's subject the way the requesting client sees it, so it can be compared against the end user the original request named.
statusNotifier IBackChannelLongPollingService
Notifier for long-polling status changes (null if long-polling disabled).
Properties
BackChannelAuthenticationGrantHandler.GrantTypesSupported Property
Specifies the grant types supported by this handler, specifically the "CIBA" (Client-Initiated Backchannel Authentication) grant type. This property ensures that the handler is only invoked for the specific grant type it supports.
public System.Collections.Generic.IEnumerable<string> GrantTypesSupported { get; }Implements GrantTypesSupported
Property Value
System.Collections.Generic.IEnumerable<System.String>
Methods
BackChannelAuthenticationGrantHandler.AuthorizeAsync(TokenRequest, ClientInfo, CancellationToken) Method
Processes the authorization request by verifying the authentication request ID and checking the status of the associated backchannel authentication request. Supports both short-polling (immediate response) and optional long-polling (holds connection until authentication completes or timeout).
public System.Threading.Tasks.Task<Abblix.Utils.Result<Abblix.Oidc.Server.Endpoints.Token.Interfaces.AuthorizedGrant,Abblix.Oidc.Server.Common.OidcError>> AuthorizeAsync(Abblix.Oidc.Server.Model.TokenRequest request, Abblix.Oidc.Server.Features.ClientInformation.ClientInfo clientInfo, System.Threading.CancellationToken cancellationToken);Parameters
request TokenRequest
The token request containing the authentication request ID and other parameters.
clientInfo ClientInfo
Information about the client making the request, used to validate client identity and determine token delivery mode (poll/ping/push).
cancellationToken System.Threading.CancellationToken
Abandons the operation when the caller stops waiting.
Implements AuthorizeAsync(TokenRequest, ClientInfo, CancellationToken)
Returns
System.Threading.Tasks.Task<Abblix.Utils.Result<AuthorizedGrant,OidcError>>
Either an authorized grant if authentication succeeded, or an error indicating why the request failed
(authorization_pending, access_denied, expired_token, slow_down, or invalid_grant).
Remarks
Behavior by Authentication Status:
- Authenticated:
- Pending (short-polling):
- Pending (long-polling):
- Denied:
- Expired/Not Found:
- Rate Limited:
Long-polling reduces latency (0-1s vs 0-5s) and server load (1-4 req/min vs 12 req/min) by holding the connection open until authentication completes instead of requiring repeated polling.