AuthenticationCompletionHandler Class
Abstract base class for CIBA authentication completion handlers. Provides common functionality for validation, status management, and delivery orchestration. Derived classes implement specific token delivery modes (poll, ping, push) per CIBA specification.
public abstract class AuthenticationCompletionHandlerInheritance System.Object → AuthenticationCompletionHandler
Derived
↳ PingModeCompletionHandler
↳ PollModeCompletionHandler
↳ PushModeCompletionHandler
Remarks
Do not add a converter-less constructor overload for the convenience of a derived class: it would compile and silently lose the comparison in CompleteAuthenticationAsync(string, BackChannelAuthenticationRequest, ClientInfo, TimeSpan), which is what keeps a request from being answered for an end user it did not name.
Methods
AuthenticationCompletionHandler.CompleteAuthenticationAsync(string, BackChannelAuthenticationRequest, ClientInfo, TimeSpan) Method
Completes the authentication process by marking the request as authenticated and delegating to the mode-specific delivery implementation.
public System.Threading.Tasks.Task CompleteAuthenticationAsync(string authenticationRequestId, Abblix.Oidc.Server.Features.BackChannelAuthentication.BackChannelAuthenticationRequest request, Abblix.Oidc.Server.Features.ClientInformation.ClientInfo clientInfo, System.TimeSpan expiresIn);Parameters
authenticationRequestId System.String
The auth_req_id identifying the authentication request.
request BackChannelAuthenticationRequest
The authentication request carrying the grant the end user approved. Its own Status is not read: whether this request may still be answered is decided from the STORED record, so a caller cannot make the decision by setting a field on its own copy.
clientInfo ClientInfo
Client information including delivery mode configuration.
expiresIn System.TimeSpan
How long the authenticated request remains valid.
Returns
System.Threading.Tasks.Task
A task representing the asynchronous authentication completion operation.
Exceptions
System.InvalidOperationException
The store does not hold a PENDING record under this
identifier. The full statement of the condition, and why it is stated that way rather than as a
list of causes, is on CompleteAsync(string, BackChannelAuthenticationRequest, TimeSpan).
Remarks
This method:
- Refuses unless the STORED record reads Pending
- Refuses an answer from somebody other than the end user the request named, by denying or removing according to the mode
- Sets the request status to Authenticated
- Delegates to HandleDeliveryAsync for mode-specific token delivery (poll/ping/push)
Called by AuthenticationCompletionRouter after determining the appropriate delivery mode handler.