SecurityProfileConsistency Class
Checks whether a client's configuration can actually satisfy the profile it selects, so a contradiction surfaces loudly at registration or startup instead of as a per-request rejection the operator has to reverse-engineer. The runtime validators already tighten a request to the profile; this is the fail-loud companion that catches static configuration that can never produce a conformant flow in the first place.
public static class SecurityProfileConsistencyInheritance System.Object → SecurityProfileConsistency
Methods
SecurityProfileConsistency.FindViolations(IReadOnlyList<string[]>, string, SecurityProfileRequirements) Method
Returns the human-readable violations that prevent a client with the given registered response types from satisfying the effective profile, or an empty list when the configuration is self-consistent. The check operates on response types because that is the one part of a FAPI client the profile cannot silently fix at request time: a client that never permits the authorization-code response type, or that permits an implicit/hybrid one, is misconfigured rather than merely tightened.
public static System.Collections.Generic.IReadOnlyList<string> FindViolations(System.Collections.Generic.IReadOnlyList<string[]> allowedResponseTypes, string tokenEndpointAuthMethod, Abblix.Oidc.Server.Features.ClientInformation.SecurityProfileRequirements requirements);Parameters
allowedResponseTypes System.Collections.Generic.IReadOnlyList<System.String[]>
The response-type combinations the client is registered for.
tokenEndpointAuthMethod System.String
How the client authenticates at the token endpoint.
requirements SecurityProfileRequirements
The control bundle the client is held to, floor included.
Returns
System.Collections.Generic.IReadOnlyList<System.String>
Remarks
The BUNDLE rather than a profile name, because a client is held to the deployment's profile tightened by its own and no enum value names that combination. Taking a name here would put the resolution inside this method, where it would silently undo whichever floor its caller had just applied - and the two controls below are the ones nothing else enforces, so the gap would show up as a client authenticating with a shared secret under a profile that admits no such client.