Saltar al contenido
Esta página aún no está traducida.

RegistrationAccessTokenValidator Class

Default implementation of IRegistrationAccessTokenValidator. Requires a Bearer scheme, validates the JWT signature and lifetime via IAuthServiceJwtValidator (which requires the audience to name this server, the party that reads the token), then enforces that the token's typ is registration_access_token and that its sub equals the requested client_id - the claim carrying the association RFC 7592 Section 1.2 describes.

C#
public class RegistrationAccessTokenValidator : Abblix.Oidc.Server.Endpoints.DynamicClientManagement.Interfaces.IRegistrationAccessTokenValidator

Inheritance System.Object → RegistrationAccessTokenValidator

Implements IRegistrationAccessTokenValidator

Constructors

RegistrationAccessTokenValidator(IAuthServiceJwtValidator) Constructor

Default implementation of IRegistrationAccessTokenValidator. Requires a Bearer scheme, validates the JWT signature and lifetime via IAuthServiceJwtValidator (which requires the audience to name this server, the party that reads the token), then enforces that the token's typ is registration_access_token and that its sub equals the requested client_id - the claim carrying the association RFC 7592 Section 1.2 describes.

C#
public RegistrationAccessTokenValidator(Abblix.Oidc.Server.Features.Tokens.Validation.IAuthServiceJwtValidator jwtValidator);

Parameters

jwtValidator IAuthServiceJwtValidator

JWT validator used for signature and lifetime checks.

Methods

RegistrationAccessTokenValidator.ValidateAsync(AuthenticationHeaderValue, string, string) Method

Validates the bearer token, ensuring it is well-formed, of the expected type, and authorized to manage the specified client.

C#
public System.Threading.Tasks.Task<string?> ValidateAsync(System.Net.Http.Headers.AuthenticationHeaderValue? header, string clientId, string? expectedTokenId);

Parameters

header System.Net.Http.Headers.AuthenticationHeaderValue

The HTTP Authorization header carrying the bearer token.

clientId System.String

The client_id targeted by the management request.

expectedTokenId System.String

The jti the token must carry to be accepted - the value stored on the client when its current registration access token was issued. When null the binding is not enforced (statically configured client, or a record predating the stored id) and only signature, type and audience are checked.

Implements ValidateAsync(AuthenticationHeaderValue, string, string)

Returns

System.Threading.Tasks.Task<System.String>
null when the token is valid for the client; otherwise a human-readable description of the validation failure.