Saltar al contenido
Esta página aún no está traducida.

BackChannelRequestStorage Class

Implements the storage of backchannel authentication requests, allowing for persistence and retrieval of authentication request data in the context of Client-Initiated Backchannel Authentication (CIBA).

C#
public class BackChannelRequestStorage : Abblix.Oidc.Server.Features.BackChannelAuthentication.Interfaces.IBackChannelRequestStorage

Inheritance System.Object → BackChannelRequestStorage

Implements IBackChannelRequestStorage

Constructors

BackChannelRequestStorage(IEntityStorage, IAuthenticationRequestIdGenerator, IEntityStorageKeyFactory) Constructor

Implements the storage of backchannel authentication requests, allowing for persistence and retrieval of authentication request data in the context of Client-Initiated Backchannel Authentication (CIBA).

C#
public BackChannelRequestStorage(Abblix.Oidc.Server.Features.Storages.IEntityStorage storage, Abblix.Oidc.Server.Features.BackChannelAuthentication.Interfaces.IAuthenticationRequestIdGenerator authenticationRequestIdGenerator, Abblix.Oidc.Server.Features.Storages.IEntityStorageKeyFactory keyFactory);

Parameters

storage IEntityStorage

The storage system used for persisting authentication requests.

authenticationRequestIdGenerator IAuthenticationRequestIdGenerator

Generator for creating unique authentication request IDs.

keyFactory IEntityStorageKeyFactory

The factory for generating standardized storage keys.

Methods

BackChannelRequestStorage.StoreAsync(BackChannelAuthenticationRequest, TimeSpan) Method

Asynchronously stores a backchannel authentication request and generates a unique identifier for it. This method also sets an expiration duration for the stored request.

C#
public System.Threading.Tasks.Task<string> StoreAsync(Abblix.Oidc.Server.Features.BackChannelAuthentication.BackChannelAuthenticationRequest authenticationRequest, System.TimeSpan expiresIn);

Parameters

authenticationRequest BackChannelAuthenticationRequest

The backchannel authentication request to store.

expiresIn System.TimeSpan

The duration after which the stored request will expire.

Implements StoreAsync(BackChannelAuthenticationRequest, TimeSpan)

Returns

System.Threading.Tasks.Task<System.String>
A task that returns the unique ID of the stored authentication request.

BackChannelRequestStorage.TryGetAsync(string) Method

Tries to retrieve a backchannel authentication request by its unique identifier.

C#
public System.Threading.Tasks.Task<Abblix.Oidc.Server.Features.BackChannelAuthentication.BackChannelAuthenticationRequest?> TryGetAsync(string authenticationRequestId);

Parameters

authenticationRequestId System.String

The unique identifier of the authentication request to retrieve.

Implements TryGetAsync(string)

Returns

System.Threading.Tasks.Task<BackChannelAuthenticationRequest>
A task that returns the authentication request if found; otherwise, null.

BackChannelRequestStorage.TryRemoveAsync(string) Method

Retrieves and removes a backchannel authentication request from storage, through the store's claim protocol. The claim is what keeps two polls from both being told they took the same request; the per-key gate around the removal is what keeps a contended key from ending with NEITHER of them told. The value is read under that same hold, so a poll is handed the bytes the removal took rather than the ones it read on its way in.

That is the whole of what the hold buys, and it is narrower than "no write is lost". Only the read and the removal are inside it: UpdateAsync(string, BackChannelAuthenticationRequest, TimeSpan) is a plain set on this key and takes no gate, so a write from the CIBA grant handler's next-poll bump can still land after the in-gate read and be destroyed by the removal without ever being seen - which that handler's own remarks already treat as an ordinary race. Closing THAT needs the writers to take the gate too, not a wider claim here.

C#
public System.Threading.Tasks.Task<Abblix.Oidc.Server.Features.BackChannelAuthentication.BackChannelAuthenticationRequest?> TryRemoveAsync(string authenticationRequestId);

Parameters

authenticationRequestId System.String

The unique identifier of the authentication request to remove.

Implements TryRemoveAsync(string)

Returns

System.Threading.Tasks.Task<BackChannelAuthenticationRequest>
A task that returns the authentication request when this caller removed it and still held its own claim afterwards. Null otherwise, and that covers more than a competitor: the request not being there, and a claim that expired while a store call was in flight - the second on one caller with nobody to lose to, its outcome being the request gone with nobody able to be told they took it. A store call that fails after the removal raises instead of answering.

BackChannelRequestStorage.UpdateAsync(string, BackChannelAuthenticationRequest, TimeSpan) Method

Updates an existing backchannel authentication request in storage. Used in ping mode to update request status when user completes authentication.

C#
public System.Threading.Tasks.Task UpdateAsync(string requestId, Abblix.Oidc.Server.Features.BackChannelAuthentication.BackChannelAuthenticationRequest request, System.TimeSpan expiresIn);

Parameters

requestId System.String

The unique identifier of the authentication request to update.

request BackChannelAuthenticationRequest

The updated authentication request data.

expiresIn System.TimeSpan

The duration after which the request expires.

Implements UpdateAsync(string, BackChannelAuthenticationRequest, TimeSpan)

Returns

System.Threading.Tasks.Task
A task that completes when the request is updated in storage.