ServiceCollectionExtensions Class
Provides extension methods for Microsoft.Extensions.DependencyInjection.IServiceCollection to register JwT-related services within the application.
public static class ServiceCollectionExtensionsInheritance System.Object → ServiceCollectionExtensions
Methods
ServiceCollectionExtensions.AddCriticalHeaderHandler<THandler>(this IServiceCollection, string) Method
Registers an ICriticalHeaderHandler for a single JOSE header extension parameter listed in a JWS 'crit' array (RFC 7515 §4.1.11). The parameter name is the DI key, so the registration cannot claim a name without a handler behind it - name and behaviour are inseparable.
public static Microsoft.Extensions.DependencyInjection.IServiceCollection AddCriticalHeaderHandler<THandler>(this Microsoft.Extensions.DependencyInjection.IServiceCollection services, string headerName)
where THandler : class, Abblix.Jwt.ICriticalHeaderHandler;Type parameters
THandler
Concrete handler type.
Parameters
services Microsoft.Extensions.DependencyInjection.IServiceCollection
The service collection to register the handler in.
headerName System.String
The JOSE header parameter name the handler implements (byte-exact per RFC 7515 §5.3); used as the DI key the validator routes a 'crit' name to. A handler covering a family of related names registers under each.
Returns
Microsoft.Extensions.DependencyInjection.IServiceCollection
The service collection for method chaining.
Remarks
Keyed-name DI mirrors the signer/encryptor registrations in this assembly
(Abblix.Jwt.ServiceCollectionExtensions.AddSignatureAlgorithm<>.Extensions.DependencyInjection.IServiceCollection,System.String) by 'alg'): one keyed registration serves
O(1) request-time dispatch (GetKeyedService<ICriticalHeaderHandler>(name)).
Microsoft.Extensions.DependencyInjection.Extensions.ServiceCollectionDescriptorExtensions.TryAddKeyedSingleton<>.Extensions.DependencyInjection.IServiceCollection,System.Object)
dedups by (service, key) first-wins, so a host pre-registration for a name wins over a
later default.
ServiceCollectionExtensions.AddJsonWebTokens(this IServiceCollection) Method
Registers services for creating and validating JSON Web Tokens (JWTs) within the application.
public static Microsoft.Extensions.DependencyInjection.IServiceCollection AddJsonWebTokens(this Microsoft.Extensions.DependencyInjection.IServiceCollection services);Parameters
services Microsoft.Extensions.DependencyInjection.IServiceCollection
The Microsoft.Extensions.DependencyInjection.IServiceCollection to configure with JWT services.
Returns
Microsoft.Extensions.DependencyInjection.IServiceCollection
The configured Microsoft.Extensions.DependencyInjection.IServiceCollection, enabling further chaining of service registrations.
Remarks
This method adds services for JWT handling, enabling the application to generate and validate JWTs efficiently. JWTs are an essential part of modern web application security, used for representing claims securely between two parties.
By registering these services, the application can: - Create JWTs with IJsonWebTokenCreator, allowing for the generation of tokens that can securely transmit information between parties. - Validate JWTs with IJsonWebTokenValidator, ensuring that incoming tokens are valid and have not been tampered with.
This setup is crucial for implementing authentication and authorization mechanisms that rely on JWTs, such as OAuth 2.0 and OpenID Connect.
ServiceCollectionExtensions.AddPbes2KeyManagement(this IServiceCollection) Method
Enables the PBES2 password-based key management algorithms (PBES2-HS256+A128KW, PBES2-HS384+A192KW, PBES2-HS512+A256KW; RFC 7518 Section 4.8) for both producing and consuming JWE tokens. They are deliberately not part of AddJsonWebTokens(this IServiceCollection): the 'p2c' header of an inbound token dictates PBKDF2 work performed before any authentication of the token (the CVE-2022-36083 class of denial of service), and because JWE decryption keys are matched by key identifier, an octet key configured for another key-management algorithm could otherwise be driven into the PBKDF2 path by an attacker-chosen 'alg' header. Accepting password-based key management is therefore an explicit hosting decision. The iteration count of an inbound token is bounded to [1000, 10,000] even when enabled.
public static Microsoft.Extensions.DependencyInjection.IServiceCollection AddPbes2KeyManagement(this Microsoft.Extensions.DependencyInjection.IServiceCollection services);Parameters
services Microsoft.Extensions.DependencyInjection.IServiceCollection
The service collection to register the PBES2 encryptors in.
Returns
Microsoft.Extensions.DependencyInjection.IServiceCollection
The service collection for method chaining.
ServiceCollectionExtensions.AddRsaPkcs1KeyManagement(this IServiceCollection) Method
Enables the RSA1_5 (RSAES-PKCS1-v1_5) key management algorithm (RFC 7518 Section 4.2) for both producing and consuming JWE tokens. It is deliberately not part of AddJsonWebTokens(this IServiceCollection): NIST SP 800-131A Rev. 2 disallows RSA key transport with PKCS#1 v1.5 padding after 2023, and RFC 8725 §3.2 prescribes preferring RSAES-OAEP - interoperating with a legacy peer that still requires it is an explicit hosting decision. The padding's Bleichenbacher decryption oracle stays closed for opted-in hosts by the RFC 7516 §11.5 mitigation in Abblix.Jwt.JsonWebTokenEncryptor: a CEK that fails to decrypt is replaced with a random CEK and the AEAD step still runs, so a decryption failure is processed identically regardless of padding validity.
public static Microsoft.Extensions.DependencyInjection.IServiceCollection AddRsaPkcs1KeyManagement(this Microsoft.Extensions.DependencyInjection.IServiceCollection services);Parameters
services Microsoft.Extensions.DependencyInjection.IServiceCollection
The service collection to register the encryptor in.
Returns
Microsoft.Extensions.DependencyInjection.IServiceCollection
The service collection for method chaining.
ServiceCollectionExtensions.ComposeExternalKeyBackends(this IServiceCollection) Method
Registers the external backends for the wired IKeyCustodian - Abblix.Jwt.ExternalKeys.ExternalKeySigner on the signing seam and Abblix.Jwt.ExternalKeys.ExternalKeyDecryptor on the key-recovery seam - and composes each with its in-process peer, so a key routes to the backend that owns it: a public-only signing key routes its signing to the custodian, a public-only decryption key routes its unwrap or ECDH-ES agreement there, and keys carrying their private material keep working in process.
public static Microsoft.Extensions.DependencyInjection.IServiceCollection ComposeExternalKeyBackends(this Microsoft.Extensions.DependencyInjection.IServiceCollection services);Parameters
services Microsoft.Extensions.DependencyInjection.IServiceCollection
Returns
Microsoft.Extensions.DependencyInjection.IServiceCollection
Remarks
The raw seam, for a host that manages key material entirely on its own terms. It records no key placement,
which makes it the wrong call inside an OpenID Provider: that server refuses to serve keys once a custodian
is registered and no placement was named, so /jwks and every token issuance would fail. Such a host
calls AddCustodian<TCustodian>(this IServiceCollection) and a
placement, which perform this too. Never both: Compose refuses the second composition on the spot.
Call after AddJsonWebTokens(this IServiceCollection), whose in-process backends this composes with. Register the custodian first, by any means the container accepts - it is resolved, not passed in here.