Skip to content

BackChannelAuthenticationGrantHandler Class

Handles the authorization process for backchannel authentication requests under the Client-Initiated Backchannel Authentication (CIBA) grant type. This handler validates the token request based on the backchannel authentication flow, ensuring that the client is authorized and that the user has been authenticated before tokens are issued. Supports both short-polling (immediate response) and long-polling (holds connection until auth completes).

C#
public class BackChannelAuthenticationGrantHandler : Abblix.Oidc.Server.Endpoints.Token.Grants.IAuthorizationGrantHandler, Abblix.Oidc.Server.Common.Interfaces.IGrantTypeInformer

Inheritance System.Object → BackChannelAuthenticationGrantHandler

Implements IAuthorizationGrantHandler, IGrantTypeInformer

Constructors

BackChannelAuthenticationGrantHandler(ILogger<BackChannelAuthenticationGrantHandler>, IBackChannelRequestStorage, IAuthorizationDetailsPolicy, TimeProvider, IOptions<OidcOptions>, IServiceProvider, ISubjectTypeConverter, IBackChannelLongPollingService) Constructor

Handles the authorization process for backchannel authentication requests under the Client-Initiated Backchannel Authentication (CIBA) grant type. This handler validates the token request based on the backchannel authentication flow, ensuring that the client is authorized and that the user has been authenticated before tokens are issued. Supports both short-polling (immediate response) and long-polling (holds connection until auth completes).

C#
public BackChannelAuthenticationGrantHandler(Microsoft.Extensions.Logging.ILogger<Abblix.Oidc.Server.Endpoints.Token.Grants.BackChannelAuthenticationGrantHandler> logger, Abblix.Oidc.Server.Features.BackChannelAuthentication.Interfaces.IBackChannelRequestStorage storage, Abblix.Oidc.Server.Features.RichAuthorizationRequests.IAuthorizationDetailsPolicy authorizationDetailsPolicy, System.TimeProvider timeProvider, Microsoft.Extensions.Options.IOptions<Abblix.Oidc.Server.Common.Configuration.OidcOptions> options, System.IServiceProvider serviceProvider, Abblix.Oidc.Server.Features.PairwiseIdentifiers.ISubjectTypeConverter subjectTypeConverter, Abblix.Oidc.Server.Features.BackChannelAuthentication.Interfaces.IBackChannelLongPollingService? statusNotifier=null);

Parameters

logger Microsoft.Extensions.Logging.ILogger<BackChannelAuthenticationGrantHandler>

Records a refusal the client is deliberately told nothing specific about.

storage IBackChannelRequestStorage

Service for storing and retrieving backchannel authentication requests.

authorizationDetailsPolicy IAuthorizationDetailsPolicy

Asks the per-type validators whether the grant's authorization_details are still acceptable, which is the only comparison that can see inside an entry.

timeProvider System.TimeProvider

Provides access to the current time.

options Microsoft.Extensions.Options.IOptions<OidcOptions>

Configuration options for backchannel authentication including long-polling settings.

serviceProvider System.IServiceProvider

Service provider for resolving mode-specific grant processors.

subjectTypeConverter ISubjectTypeConverter

Seals the authenticated session's subject the way the requesting client sees it, so it can be compared against the end user the original request named.

statusNotifier IBackChannelLongPollingService

Notifier for long-polling status changes (null if long-polling disabled).

Properties

BackChannelAuthenticationGrantHandler.GrantTypesSupported Property

Specifies the grant types supported by this handler, specifically the "CIBA" (Client-Initiated Backchannel Authentication) grant type. This property ensures that the handler is only invoked for the specific grant type it supports.

C#
public System.Collections.Generic.IEnumerable<string> GrantTypesSupported { get; }

Implements GrantTypesSupported

Property Value

System.Collections.Generic.IEnumerable<System.String>

Methods

BackChannelAuthenticationGrantHandler.AuthorizeAsync(TokenRequest, ClientInfo, CancellationToken) Method

Processes the authorization request by verifying the authentication request ID and checking the status of the associated backchannel authentication request. Supports both short-polling (immediate response) and optional long-polling (holds connection until authentication completes or timeout).

C#
public System.Threading.Tasks.Task<Abblix.Utils.Result<Abblix.Oidc.Server.Endpoints.Token.Interfaces.AuthorizedGrant,Abblix.Oidc.Server.Common.OidcError>> AuthorizeAsync(Abblix.Oidc.Server.Model.TokenRequest request, Abblix.Oidc.Server.Features.ClientInformation.ClientInfo clientInfo, System.Threading.CancellationToken cancellationToken);

Parameters

request TokenRequest

The token request containing the authentication request ID and other parameters.

clientInfo ClientInfo

Information about the client making the request, used to validate client identity and determine token delivery mode (poll/ping/push).

cancellationToken System.Threading.CancellationToken

Abandons the operation when the caller stops waiting.

Implements AuthorizeAsync(TokenRequest, ClientInfo, CancellationToken)

Returns

System.Threading.Tasks.Task<Abblix.Utils.Result<AuthorizedGrant,OidcError>>
Either an authorized grant if authentication succeeded, or an error indicating why the request failed (authorization_pending, access_denied, expired_token, slow_down, or invalid_grant).

Remarks

Behavior by Authentication Status:

  • Authenticated:
  • Pending (short-polling):
  • Pending (long-polling):
  • Denied:
  • Expired/Not Found:
  • Rate Limited:

Long-polling reduces latency (0-1s vs 0-5s) and server load (1-4 req/min vs 12 req/min) by holding the connection open until authentication completes instead of requiring repeated polling.