Zum Inhalt springen
Diese Seite wurde noch nicht übersetzt.

IDeviceAuthorizationStorage Interface

Defines the contract for a storage system responsible for persisting and retrieving device authorization requests as defined in RFC 8628.

C#
public interface IDeviceAuthorizationStorage

Derived
↳ DeviceAuthorizationStorage

Methods

IDeviceAuthorizationStorage.RemoveAsync(string) Method

Removes a device authorization request from storage using its device code.

C#
System.Threading.Tasks.Task RemoveAsync(string deviceCode);

Parameters

deviceCode System.String

The device code identifier.

Returns

System.Threading.Tasks.Task
A task that completes when the request is removed. Tidying the secondary user-code index is best-effort and is logged rather than raised: it is not what the caller asked for, and a store deciding otherwise must not become a fault where a grant error belongs. Removing the request itself is not guarded - that IS what was asked, so a refusal there raises.

IDeviceAuthorizationStorage.StoreAsync(string, DeviceAuthorizationRequest, TimeSpan) Method

Stores a device authorization request with the specified device code.

C#
System.Threading.Tasks.Task StoreAsync(string deviceCode, Abblix.Oidc.Server.Features.DeviceAuthorization.DeviceAuthorizationRequest request, System.TimeSpan expiresIn);

Parameters

deviceCode System.String

The unique device code identifier.

request DeviceAuthorizationRequest

The device authorization request to store.

expiresIn System.TimeSpan

The duration after which the stored request will expire.

Returns

System.Threading.Tasks.Task
A task that completes when the request is stored.

IDeviceAuthorizationStorage.TryGetByDeviceCodeAsync(string) Method

Tries to retrieve a device authorization request by its device code. This is used by the client when polling the token endpoint.

C#
System.Threading.Tasks.Task<Abblix.Oidc.Server.Features.DeviceAuthorization.DeviceAuthorizationRequest?> TryGetByDeviceCodeAsync(string deviceCode);

Parameters

deviceCode System.String

The device code identifier.

Returns

System.Threading.Tasks.Task<DeviceAuthorizationRequest>
A task that returns the device authorization request if found; otherwise, null.

IDeviceAuthorizationStorage.TryGetByUserCodeAsync(string) Method

Tries to retrieve a device authorization request by its user code. This is used during user verification to look up the pending request.

C#
System.Threading.Tasks.Task<System.Nullable<(string DeviceCode,Abblix.Oidc.Server.Features.DeviceAuthorization.DeviceAuthorizationRequest Request)>> TryGetByUserCodeAsync(string userCode);

Parameters

userCode System.String

The user-friendly verification code.

Returns

System.Threading.Tasks.Task<System.Nullable<<System.String,DeviceAuthorizationRequest>>>
A task that returns the device code and request if found; otherwise, null.

IDeviceAuthorizationStorage.TryRemoveAsync(string, string) Method

Claims a device authorization request by its device code, deciding presence and removing it in one protocol, so that a caller told it removed the request is the only caller that can be told so. It narrows that window rather than closing it; the returns block below says what a false covers.

C#
System.Threading.Tasks.Task<bool> TryRemoveAsync(string deviceCode, string userCode);

Parameters

deviceCode System.String

The device code identifier.

userCode System.String

The user code for cleaning up the secondary index mapping.

Returns

System.Threading.Tasks.Task<System.Boolean>
A task that returns true when this caller removed the request AND still held its own claim afterwards. False otherwise, which is wider than "somebody else got it": it also covers the request not being there and a claim that expired while a store call was in flight - the second on one caller with nobody to lose to, and its outcome is the request gone with nobody able to be told they took it. An operator told a second REQUEST was the cause goes looking for one, and the expiry case is exactly the one that never produces a second request.

Removing the secondary user-code index is not part of that answer. It runs after the claim has already decided, so a store that refuses it is logged and the answer stands. The entry left behind expires on its own; what it still resolves to depends on the user code the caller passed, which this method never checks against the record it removed.

IDeviceAuthorizationStorage.UpdateAsync(string, DeviceAuthorizationRequest, TimeSpan) Method

Updates an existing device authorization request in storage, refreshing its cache entry with the caller-supplied remaining lifetime.

C#
System.Threading.Tasks.Task UpdateAsync(string deviceCode, Abblix.Oidc.Server.Features.DeviceAuthorization.DeviceAuthorizationRequest request, System.TimeSpan expiresIn);

Parameters

deviceCode System.String

The device code identifier.

request DeviceAuthorizationRequest

The updated device authorization request.

expiresIn System.TimeSpan

The remaining lifetime to apply as the cache TTL. The caller derives it from the request's fixed expiry (RFC 8628 section 3.2) so that repeated polling cannot extend the code.

Returns

System.Threading.Tasks.Task
A task that completes when the request is updated.