Zum Inhalt springen
Diese Seite wurde noch nicht übersetzt.

ProofErrorReasons Class

Stable, machine-friendly reason tokens that Abblix.Oidc.Server.Features.DPoP.ProofValidator assigns to Reason for log filters and metric labels. These are the internal fine-grained failure categories; the OAuth-protocol-level error code surfaced to clients is always invalid_dpop_proof (or use_dpop_nonce for the nonce-required path) regardless of which of these matched.

C#
public static class ProofErrorReasons

Inheritance System.Object → ProofErrorReasons

Fields

ProofErrorReasons.AccessTokenHashMismatch Field

Payload ath does not match Base64Url(SHA-256(access_token)).

C#
public const string AccessTokenHashMismatch = "ath_mismatch";

Field Value

System.String

ProofErrorReasons.AccessTokenHashMissing Field

Payload ath claim is required (an access token is presented) but missing.

C#
public const string AccessTokenHashMissing = "ath_missing";

Field Value

System.String

ProofErrorReasons.HttpMethodMismatch Field

Payload htm does not match the request method.

C#
public const string HttpMethodMismatch = "htm_mismatch";

Field Value

System.String

ProofErrorReasons.HttpUriInvalid Field

Payload htu is not a valid absolute URI.

C#
public const string HttpUriInvalid = "htu_invalid";

Field Value

System.String

ProofErrorReasons.HttpUriMismatch Field

Payload htu does not match the request URI after RFC 3986 §6.2 canonicalisation.

C#
public const string HttpUriMismatch = "htu_mismatch";

Field Value

System.String

ProofErrorReasons.HttpUriMissing Field

Payload htu claim is missing.

C#
public const string HttpUriMissing = "htu_missing";

Field Value

System.String

ProofErrorReasons.InvalidAlgorithm Field

Header alg is missing, not asymmetric, or not in the configured whitelist.

C#
public const string InvalidAlgorithm = "invalid_alg";

Field Value

System.String

ProofErrorReasons.InvalidHeader Field

A JOSE header parameter is malformed or violates a structural rule.

C#
public const string InvalidHeader = "invalid_header";

Field Value

System.String

Remarks

Deliberately named for the header rather than for one member of it: this is what the JWT core's InvalidHeader becomes, and that category covers an unusable jwk, a crit that is malformed or names an extension nothing handles, and a header a trust model requires and the token omits. Reporting all three as invalid_jwk told a client its key was bad over a crit it had written itself.

WHICH of the three happened is on Detail and goes no further - no response, no log, no metric label. That is a decision rather than an omission: two of the core's crit descriptions are written by quoting the token, so the value carries what the client put there, and the rest are constants that cannot be told apart from them at this seam.

The cost is stated rather than hidden: for all three causes a client is told invalid_header and an operator's log line says the same, so nothing the library emits separates an unusable jwk from a bad crit. A host that wants the difference reads Detail off its own call - and sanitises it, because it may be the client's own bytes.

ProofErrorReasons.InvalidJwk Field

Header jwk is missing, malformed, or contains private-key material.

C#
public const string InvalidJwk = "invalid_jwk";

Field Value

System.String

Remarks

Only where THIS validator establishes it. A refusal that came from the JWT core arrives under InvalidHeader instead, because the core reports a bad jwk, a bad crit and a missing required header under one category and cannot tell a consumer which it met.

ProofErrorReasons.InvalidTokenType Field

Header typ is not dpop+jwt.

C#
public const string InvalidTokenType = "invalid_typ";

Field Value

System.String

ProofErrorReasons.IssuedAtInvalid Field

Payload iat is not a Unix-time numeric.

C#
public const string IssuedAtInvalid = "iat_invalid";

Field Value

System.String

ProofErrorReasons.IssuedAtMissing Field

Payload iat claim is missing.

C#
public const string IssuedAtMissing = "iat_missing";

Field Value

System.String

ProofErrorReasons.IssuedAtOutOfWindow Field

Payload iat falls outside the configured tolerance window around the current time.

C#
public const string IssuedAtOutOfWindow = "iat_out_of_window";

Field Value

System.String

ProofErrorReasons.JwtIdMissing Field

Payload jti claim is missing.

C#
public const string JwtIdMissing = "jti_missing";

Field Value

System.String

ProofErrorReasons.MalformedJwt Field

JWS compact form is not three dot-separated segments, base64url-decode failed, or the header/payload is not a JSON object.

C#
public const string MalformedJwt = "malformed_jwt";

Field Value

System.String

ProofErrorReasons.ReplayDetected Field

Payload jti has already been used within the acceptance window.

C#
public const string ReplayDetected = "replay_detected";

Field Value

System.String

ProofErrorReasons.SignatureInvalid Field

JWS signature does not verify under the embedded jwk.

C#
public const string SignatureInvalid = "signature_invalid";

Field Value

System.String