Saltar al contenido
Esta página aún no está traducida.

AuthorizationValidationContext Class

Encapsulates the context necessary for validating an authorization request, including client details, response modes, and the OAuth 2.0 flow type.

C#
public record AuthorizationValidationContext : System.IEquatable<Abblix.Oidc.Server.Endpoints.Authorization.Validation.AuthorizationValidationContext>

Inheritance System.Object → AuthorizationValidationContext

Implements System.IEquatable<AuthorizationValidationContext>

Constructors

AuthorizationValidationContext(AuthorizationRequest) Constructor

Encapsulates the context necessary for validating an authorization request, including client details, response modes, and the OAuth 2.0 flow type.

C#
public AuthorizationValidationContext(Abblix.Oidc.Server.Model.AuthorizationRequest Request);

Parameters

Request AuthorizationRequest

Properties

AuthorizationValidationContext.AuthorizationDetails Property

The RFC 9396 Rich Authorization Requests array after per-type and per-client validation by IAuthorizationDetailsPolicy, stored as the raw System.Text.Json.Nodes.JsonArray so byte-exact content survives forward to the grant. null when the request did not include authorization_details.

C#
public System.Text.Json.Nodes.JsonArray? AuthorizationDetails { get; set; }

Property Value

System.Text.Json.Nodes.JsonArray

AuthorizationValidationContext.ClientInfo Property

Provides details about the client making the authorization request. This includes identifying information such as client ID and any other relevant data that has been registered with the authorization server.

C#
public Abblix.Oidc.Server.Features.ClientInformation.ClientInfo ClientInfo { get; set; }

Property Value

ClientInfo

Exceptions

System.InvalidOperationException
Thrown when trying to access this property before it is set.

AuthorizationValidationContext.FlowType Property

Identifies the OAuth 2.0 flow used in the authorization request, such as Authorization Code or Implicit.

C#
public Abblix.Oidc.Server.Common.Constants.FlowTypes FlowType { get; set; }

Property Value

FlowTypes

Exceptions

System.InvalidOperationException
Thrown when trying to access this property before it is set.

AuthorizationValidationContext.IdTokenHintSubject Property

The end user the request's id_token_hint names, as that ID token spells it, or null when the request carried no hint.

C#
public string? IdTokenHintSubject { get; set; }

Property Value

System.String

Remarks

Spelled as the ID token has it, which for a pairwise client is the pseudonym sealed to that client's sector rather than the subject a session carries. Whoever compares the two converts the session forward; opening the pseudonym would fail whenever it could not be opened, and a comparison that could not be made must not read as a match.

AuthorizationValidationContext.Request Property

The authorization request to be validated. This includes all the details provided by the client for the authorization process.

C#
public Abblix.Oidc.Server.Model.AuthorizationRequest Request { get; set; }

Property Value

AuthorizationRequest

AuthorizationValidationContext.RequestedSubjects Property

The end users the request's claims parameter will accept for sub, or null when it asked for none in particular. An empty array accepts nobody.

C#
public string[]? RequestedSubjects { get; set; }

Property Value

System.String[]

Remarks

A second, independent constraint rather than an alternative spelling of IdTokenHintSubject: a request may carry both, and OpenID Connect Core 1.0 Section 3.1.2.2 obliges the server to honour whichever are present. Spelled the way the client wrote them, so the same conversion applies - a pairwise client names the pseudonym sealed to its own sector.

Empty is a state a request can genuinely reach, by naming a value absent from its own values. That mismatch is what Section 5.5.1 says "MUST cause the authentication to fail", so it is carried through as a constraint nobody satisfies rather than discarded as nonsense.

AuthorizationValidationContext.Resources Property

A collection of resource definitions that may be requested as part of the authorization process, providing additional control over the accessible resources.

C#
public Abblix.Oidc.Server.Common.Constants.ResourceDefinition[] Resources { get; set; }

Property Value

ResourceDefinition[]

AuthorizationValidationContext.ResponseMode Property

Specifies how the authorization response should be delivered to the client, e.g., via a direct query or fragment.

C#
public string ResponseMode { get; set; }

Property Value

System.String

AuthorizationValidationContext.Scope Property

A collection of scope definitions applicable to the authorization request, determining the permissions granted.

C#
public Abblix.Oidc.Server.Common.Constants.ScopeDefinition[] Scope { get; set; }

Property Value

ScopeDefinition[]

AuthorizationValidationContext.ValidRedirectUri Property

The redirect URI where the response to the authorization request should be sent. This URI must be one of the registered URIs for the client to ensure security.

C#
public System.Uri? ValidRedirectUri { get; set; }

Property Value

System.Uri