IAuthenticationCompletionHandler Interface
Handles CIBA authentication completion by routing to the appropriate delivery mode handler (poll, ping, or push) based on the client's configured backchannel_token_delivery_mode.
public interface IAuthenticationCompletionHandlerDerived
↳ AuthenticationCompletionRouter
Properties
IAuthenticationCompletionHandler.TokenDeliveryModesSupported Property
Token delivery modes (poll, ping, push) for which a handler is registered with the DI container.
Used to populate the discovery document's backchannel_token_delivery_modes_supported field
so it reflects only modes the host actually supports.
System.Collections.Generic.IEnumerable<string> TokenDeliveryModesSupported { get; }Property Value
System.Collections.Generic.IEnumerable<System.String>
Methods
IAuthenticationCompletionHandler.CompleteAsync(string, BackChannelAuthenticationRequest, TimeSpan) Method
Completes the authentication process and handles token delivery according to the client's configured delivery mode.
System.Threading.Tasks.Task CompleteAsync(string authenticationRequestId, Abblix.Oidc.Server.Features.BackChannelAuthentication.BackChannelAuthenticationRequest request, System.TimeSpan expiresIn);Parameters
authenticationRequestId System.String
The auth_req_id identifying the authentication request.
request BackChannelAuthenticationRequest
The authentication request carrying the grant the end user approved. Its own Status is not read: whether this request may still be answered is decided from the STORED record, so a caller cannot make the decision by setting a field on its own copy.
expiresIn System.TimeSpan
How long the authenticated request remains valid for token retrieval.
Returns
System.Threading.Tasks.Task
A task representing the asynchronous completion operation.
Exceptions
System.InvalidOperationException
The store does not hold a PENDING record under this
identifier. Stated as what must be true rather than as a list of causes, because the causes are
more numerous than they look and this seam cannot tell them apart: the request may have been
answered, refused or expired, its record may have been redeemed and removed by a poll, removed by
push's own refusal path after a configuration fault where nothing was answered at all, evicted,
or never stored. A host that persists the status itself before calling lands here too, on its
FIRST completion and with nothing over-granted.
Completing a request that is not pending would deliver a second answer for one authentication. Recovering from a failed delivery therefore means asking the end user again, not repeating the call.
Remarks
This method automatically:
- Retrieves client information to determine the delivery mode
- Selects the appropriate handler (PollModeCompletionHandler, PingModeCompletionHandler, or PushModeCompletionHandler)
- Delegates to the mode-specific implementation for token delivery