SecureHttpFetcherExtensions Class
Provides reusable functionality for fetching JSON Web Key Sets (JWKS) from remote URIs with SSRF protection and consistent error handling.
public static class SecureHttpFetcherExtensionsInheritance System.Object → SecureHttpFetcherExtensions
Methods
SecureHttpFetcherExtensions.FetchKeysAsync(this ISecureHttpFetcher, Uri, ILogger, string, string) Method
Fetches JSON Web Keys from a JWKS URI with SSRF protection and optional filtering.
public static System.Collections.Generic.IAsyncEnumerable<Abblix.Jwt.JsonWebKey> FetchKeysAsync(this Abblix.Oidc.Server.Features.SecureHttpFetch.ISecureHttpFetcher secureFetcher, System.Uri jwksUri, Microsoft.Extensions.Logging.ILogger logger, string entityId, string entityType);Parameters
secureFetcher ISecureHttpFetcher
HTTP fetcher with SSRF protection and caching.
jwksUri System.Uri
The URI to fetch the JWKS from.
logger Microsoft.Extensions.Logging.ILogger
Logger for recording fetch operations and errors.
entityId System.String
The identifier of the entity (client ID or issuer) for logging.
entityType System.String
The type of entity (e.g., "client" or "issuer") for logging.
Returns
System.Collections.Generic.IAsyncEnumerable<JsonWebKey>
An async enumerable of JSON Web Keys from the JWKS endpoint.
Returns empty if fetching fails or the JWKS is invalid.
SecureHttpFetcherExtensions.ResolveKeysAsync(this IServiceProvider, JsonWebKeySet, Uri, ILogger, string, string) Method
Resolves the keys a party publishes, in the two forms a party may publish them: inline in its registration, and at a JWKS URI. Both may be present, and the inline keys come first.
public static System.Collections.Generic.IAsyncEnumerable<Abblix.Jwt.JsonWebKey> ResolveKeysAsync(this System.IServiceProvider serviceProvider, Abblix.Jwt.JsonWebKeySet? jwks, System.Uri? jwksUri, Microsoft.Extensions.Logging.ILogger logger, string entityId, string entityType);Parameters
serviceProvider System.IServiceProvider
Used to resolve ISecureHttpFetcher, which is scoped while the providers calling this are not, so a scope is created per call rather than held.
jwks JsonWebKeySet
The key set held in the party's own registration, if any.
jwksUri System.Uri
The URI the party publishes its key set at, if any.
logger Microsoft.Extensions.Logging.ILogger
Logger for recording fetch operations and errors.
entityId System.String
The identifier of the party, for logging.
entityType System.String
What kind of party it is. Must be a value from KeySetOwners: besides labelling the log, it is the service key under which this consumer's cached fetcher is registered, so the same value selects the cache lifetime that consumer was given.
Returns
System.Collections.Generic.IAsyncEnumerable<JsonWebKey>
The inline keys followed by the fetched ones. Empty when the party declares neither.
Remarks
The fetch itself is SSRF-protected and cached by the decorators around ISecureHttpFetcher, so a caller gets both without arranging either.