ProofErrorReasons Class
Stable, machine-friendly reason tokens that Abblix.Oidc.Server.Features.DPoP.ProofValidator assigns to
Reason for log filters and metric labels. These are the
internal fine-grained failure categories; the OAuth-protocol-level error code surfaced
to clients is always invalid_dpop_proof (or use_dpop_nonce for the
nonce-required path) regardless of which of these matched.
public static class ProofErrorReasonsInheritance System.Object → ProofErrorReasons
Fields
ProofErrorReasons.AccessTokenHashMismatch Field
Payload ath does not match Base64Url(SHA-256(access_token)).
public const string AccessTokenHashMismatch = "ath_mismatch";Field Value
ProofErrorReasons.AccessTokenHashMissing Field
Payload ath claim is required (an access token is presented) but missing.
public const string AccessTokenHashMissing = "ath_missing";Field Value
ProofErrorReasons.HttpMethodMismatch Field
Payload htm does not match the request method.
public const string HttpMethodMismatch = "htm_mismatch";Field Value
ProofErrorReasons.HttpUriInvalid Field
Payload htu is not a valid absolute URI.
public const string HttpUriInvalid = "htu_invalid";Field Value
ProofErrorReasons.HttpUriMismatch Field
Payload htu does not match the request URI after RFC 3986 §6.2 canonicalisation.
public const string HttpUriMismatch = "htu_mismatch";Field Value
ProofErrorReasons.HttpUriMissing Field
Payload htu claim is missing.
public const string HttpUriMissing = "htu_missing";Field Value
ProofErrorReasons.InvalidAlgorithm Field
Header alg is missing, not asymmetric, or not in the configured whitelist.
public const string InvalidAlgorithm = "invalid_alg";Field Value
ProofErrorReasons.InvalidHeader Field
A JOSE header parameter is malformed or violates a structural rule.
public const string InvalidHeader = "invalid_header";Field Value
Remarks
Deliberately named for the header rather than for one member of it: this is what the JWT core's
InvalidHeader becomes, and that category covers an unusable jwk, a crit that
is malformed or names an extension nothing handles, and a header a trust model requires and the
token omits. Reporting all three as invalid_jwk told a client its key was bad over a
crit it had written itself.
WHICH of the three happened is on Detail and goes no further - no
response, no log, no metric label. That is a decision rather than an omission: two of the core's
crit descriptions are written by quoting the token, so the value carries what the client
put there, and the rest are constants that cannot be told apart from them at this seam.
The cost is stated rather than hidden: for all three causes a client is told invalid_header
and an operator's log line says the same, so nothing the library emits separates an unusable
jwk from a bad crit. A host that wants the difference reads
Detail off its own call - and sanitises it, because it may be the
client's own bytes.
ProofErrorReasons.InvalidJwk Field
Header jwk is missing, malformed, or contains private-key material.
public const string InvalidJwk = "invalid_jwk";Field Value
Remarks
Only where THIS validator establishes it. A refusal that came from the JWT core arrives under
InvalidHeader instead, because the core reports a bad jwk, a bad crit
and a missing required header under one category and cannot tell a consumer which it met.
ProofErrorReasons.InvalidTokenType Field
Header typ is not dpop+jwt.
public const string InvalidTokenType = "invalid_typ";Field Value
ProofErrorReasons.IssuedAtInvalid Field
Payload iat is not a Unix-time numeric.
public const string IssuedAtInvalid = "iat_invalid";Field Value
ProofErrorReasons.IssuedAtMissing Field
Payload iat claim is missing.
public const string IssuedAtMissing = "iat_missing";Field Value
ProofErrorReasons.IssuedAtOutOfWindow Field
Payload iat falls outside the configured tolerance window around the current time.
public const string IssuedAtOutOfWindow = "iat_out_of_window";Field Value
ProofErrorReasons.JwtIdMissing Field
Payload jti claim is missing.
public const string JwtIdMissing = "jti_missing";Field Value
ProofErrorReasons.MalformedJwt Field
JWS compact form is not three dot-separated segments, base64url-decode failed, or the header/payload is not a JSON object.
public const string MalformedJwt = "malformed_jwt";Field Value
ProofErrorReasons.ReplayDetected Field
Payload jti has already been used within the acceptance window.
public const string ReplayDetected = "replay_detected";Field Value
ProofErrorReasons.SignatureInvalid Field
JWS signature does not verify under the embedded jwk.
public const string SignatureInvalid = "signature_invalid";