Skip to content

EndSessionRequest Class

The transport-bound counterpart of EndSessionRequest for the RP-initiated logout endpoint, reachable via GET and POST. The bound properties, model binders resolved from the core wire-format markers and the projection back onto the core model are generated from the core type; the cross-property validation below stays hand-written because it spans several parameters at once.

C#
public record EndSessionRequest : System.ComponentModel.DataAnnotations.IValidatableObject, System.IEquatable<Abblix.Oidc.Server.Mvc.Model.EndSessionRequest>

Inheritance System.Object → EndSessionRequest

Implements System.ComponentModel.DataAnnotations.IValidatableObject, System.IEquatable<EndSessionRequest>

Properties

EndSessionRequest.ClientId Property

The client_id of the relying party initiating the logout, allowing the OP to validate PostLogoutRedirectUri against the URIs registered for that client.

C#
public string? ClientId { get; init; }

Property Value

System.String

EndSessionRequest.Confirmed Property

Carries the End-User's answer to the logout confirmation prompt that the OP is required to display per OIDC RP-Initiated Logout 1.0 §2 ("the OP SHOULD ask the End-User whether to log out ... MUST ask ... if an id_token_hint was not provided"). When true, the user has explicitly approved logout in the interactive UI; when null or false, the request is treated as not-yet-confirmed and the OP renders the confirmation screen. Encoded via the Confirmed form field rather than a wire parameter defined by the specification.

C#
public System.Nullable<bool> Confirmed { get; init; }

Property Value

System.Nullable<System.Boolean>

EndSessionRequest.IdTokenHint Property

The id_token_hint: a previously issued ID Token whose subject identifies the end-user whose session should be terminated. Recommended by RP-Initiated Logout to authenticate the logout request and to scope which session is logged out.

C#
public string? IdTokenHint { get; init; }

Property Value

System.String

EndSessionRequest.LogoutHint Property

The logout_hint: an opaque hint about the end-user's login identifier (such as username or email) the OpenID Provider may use to identify the session to terminate when an ID Token hint is unavailable.

C#
public string? LogoutHint { get; init; }

Property Value

System.String

EndSessionRequest.PostLogoutRedirectUri Property

The post_logout_redirect_uri: an absolute URI, pre-registered with the OP, to which the user agent is redirected once logout completes.

C#
public System.Uri? PostLogoutRedirectUri { get; init; }

Property Value

System.Uri

EndSessionRequest.State Property

The opaque state value returned unchanged when the user agent is sent back to PostLogoutRedirectUri, used by the relying party to correlate request and callback.

C#
public string? State { get; init; }

Property Value

System.String

EndSessionRequest.UiLocales Property

The ui_locales preference list of BCP 47 language tags hinting how the logout confirmation page should be localized.

C#
public System.Collections.Generic.IEnumerable<System.Globalization.CultureInfo>? UiLocales { get; init; }

Property Value

System.Collections.Generic.IEnumerable<System.Globalization.CultureInfo>

Methods

EndSessionRequest.Map() Method

Projects the transport-bound model onto its core counterpart, copying every bound parameter so the core pipeline operates on a transport-agnostic shape.

C#
public Abblix.Oidc.Server.Model.EndSessionRequest Map();

Returns

EndSessionRequest

EndSessionRequest.Validate(ValidationContext) Method

Validates the end session request according to OIDC RP-Initiated Logout 1.0 specification. This method is called AFTER all properties are bound, ensuring cross-property validation works correctly. Per OIDC specification: - When post_logout_redirect_uri is used without id_token_hint, client_id identifies the client - When id_token_hint is provided, the OP can extract client identity from the token - When neither are provided, the OP uses session cookies to identify the user

C#
public System.Collections.Generic.IEnumerable<System.ComponentModel.DataAnnotations.ValidationResult> Validate(System.ComponentModel.DataAnnotations.ValidationContext validationContext);

Parameters

validationContext System.ComponentModel.DataAnnotations.ValidationContext

The validation context.

Implements Validate(ValidationContext)

Returns

System.Collections.Generic.IEnumerable<System.ComponentModel.DataAnnotations.ValidationResult>
A collection of validation results.

Operators

EndSessionRequest.implicit operator EndSessionRequest(EndSessionRequest) Operator

Implicit form of Map(), letting a bound model flow into any core-typed parameter or variable without an explicit call.

C#
public static Abblix.Oidc.Server.Model.EndSessionRequest implicit operator Abblix.Oidc.Server.Model.EndSessionRequest(Abblix.Oidc.Server.Mvc.Model.EndSessionRequest request);

Parameters

request EndSessionRequest

Returns

EndSessionRequest