Skip to content

BackChannelAuthenticationRequest Class

Represents a backchannel authentication request as part of the Client-Initiated Backchannel Authentication (CIBA) protocol. This request facilitates the authentication of users without requiring immediate interaction with their devices, allowing for a more flexible and user-friendly authentication experience.

C#
public record BackChannelAuthenticationRequest : System.IEquatable<Abblix.Oidc.Server.Features.BackChannelAuthentication.BackChannelAuthenticationRequest>

Inheritance System.Object → BackChannelAuthenticationRequest

Implements System.IEquatable<BackChannelAuthenticationRequest>

Constructors

BackChannelAuthenticationRequest(AuthorizedGrant, DateTimeOffset) Constructor

Represents a backchannel authentication request as part of the Client-Initiated Backchannel Authentication (CIBA) protocol. This request facilitates the authentication of users without requiring immediate interaction with their devices, allowing for a more flexible and user-friendly authentication experience.

C#
public BackChannelAuthenticationRequest(Abblix.Oidc.Server.Endpoints.Token.Interfaces.AuthorizedGrant AuthorizedGrant, System.DateTimeOffset ExpiresAt);

Parameters

AuthorizedGrant AuthorizedGrant

The authorized grant associated with this authentication request, containing details about the user's authorization context.

ExpiresAt System.DateTimeOffset

The absolute time when this backchannel authentication request expires.

Properties

BackChannelAuthenticationRequest.AuthorizedGrant Property

The authorized grant associated with this authentication request, containing details about the user's authorization context.

C#
public Abblix.Oidc.Server.Endpoints.Token.Interfaces.AuthorizedGrant AuthorizedGrant { get; init; }

Property Value

AuthorizedGrant

BackChannelAuthenticationRequest.ClientNotificationEndpoint Property

The client notification endpoint for ping mode. Populated from client configuration when ping mode is used.

C#
public System.Uri? ClientNotificationEndpoint { get; set; }

Property Value

System.Uri

BackChannelAuthenticationRequest.ClientNotificationToken Property

The client notification token for ping mode. Provided by the client in the authentication request for secure notification delivery.

C#
public string? ClientNotificationToken { get; set; }

Property Value

System.String

BackChannelAuthenticationRequest.ExpiresAt Property

The absolute time when this backchannel authentication request expires.

C#
public System.DateTimeOffset ExpiresAt { get; init; }

Property Value

System.DateTimeOffset

BackChannelAuthenticationRequest.NextPollAt Property

Specifies the next time the client should poll for updates regarding the authentication request. This helps manage the timing of polling requests efficiently.

C#
public System.Nullable<System.DateTimeOffset> NextPollAt { get; set; }

Property Value

System.Nullable<System.DateTimeOffset>

BackChannelAuthenticationRequest.RequestedAuthorizationDetails Property

The RFC 9396 authorization_details the client asked for, as the request-time validators left them. EMPTY when the request carried none; null only on a request stored before this field existed, which is why the two are not the same answer.

C#
public System.Text.Json.Nodes.JsonArray? RequestedAuthorizationDetails { get; set; }

Property Value

System.Text.Json.Nodes.JsonArray

Remarks

Kept apart from the array on AuthorizedGrant, which is what will be issued. The two are the same until the end user answers: a host whose device UI let them approve part of the request replaces the grant's context before completing, and this is what that answer is judged against.

Recorded rather than derived, for the reason RequestedSubjects is: in a decoupled flow the answer arrives long after the request, through CompleteAsync(string, BackChannelAuthenticationRequest, TimeSpan), and by then the only copy of what was asked for would be the one the host has just overwritten.

BackChannelAuthenticationRequest.RequestedSubjects Property

The end users the request will accept, spelled as the requesting client sees them, or null when it named nobody in particular. An empty array accepts nobody.

C#
public string[]? RequestedSubjects { get; set; }

Property Value

System.String[]

Remarks

Recorded here rather than compared once and discarded, because in a decoupled flow the end user authenticates long after the request was made: the session that answers it arrives through CompleteAsync(string, BackChannelAuthenticationRequest, TimeSpan), and OpenID Connect Core 1.0 Section 3.1.2.2 forbids answering for anyone else. Without this the comparison would have nothing left to compare against by the time there is a session to judge.

A set rather than a name, because the two parameters that can name an end user do not agree on the shape: an id_token_hint names one, and a claims request may list several it would accept. Section 3.1.2.2 puts both under a single requirement, so both land here.

BackChannelAuthenticationRequest.Status Property

Indicates the current status of the backchannel authentication request. Defaults to Pending, reflecting that the request has not yet been resolved.

C#
public Abblix.Oidc.Server.Features.BackChannelAuthentication.BackChannelAuthenticationStatus Status { get; set; }

Property Value

BackChannelAuthenticationStatus