Saltar al contenido
Esta página aún no está traducida.

DeviceAuthorizationStorage Class

Implements storage for device authorization requests as defined in RFC 8628. Stores requests by device_code (for client polling) with a secondary index by user_code (for user verification). Redemption of a device code goes through the cache's claim protocol, which narrows the window in which two token requests both claim one code rather than closing it.

C#
public class DeviceAuthorizationStorage : Abblix.Oidc.Server.Features.DeviceAuthorization.Interfaces.IDeviceAuthorizationStorage

Inheritance System.Object → DeviceAuthorizationStorage

Implements IDeviceAuthorizationStorage

Constructors

DeviceAuthorizationStorage(ILogger<DeviceAuthorizationStorage>, IDistributedCache, IBinarySerializer, IEntityStorageKeyFactory, TimeProvider) Constructor

Implements storage for device authorization requests as defined in RFC 8628. Stores requests by device_code (for client polling) with a secondary index by user_code (for user verification). Redemption of a device code goes through the cache's claim protocol, which narrows the window in which two token requests both claim one code rather than closing it.

C#
public DeviceAuthorizationStorage(Microsoft.Extensions.Logging.ILogger<Abblix.Oidc.Server.Features.DeviceAuthorization.DeviceAuthorizationStorage> logger, Microsoft.Extensions.Caching.Distributed.IDistributedCache cache, Abblix.Oidc.Server.Common.Interfaces.IBinarySerializer serializer, Abblix.Oidc.Server.Features.Storages.IEntityStorageKeyFactory keyFactory, System.TimeProvider timeProvider);

Parameters

logger Microsoft.Extensions.Logging.ILogger<DeviceAuthorizationStorage>

Records a secondary-index entry left behind, which nothing else reports.

cache Microsoft.Extensions.Caching.Distributed.IDistributedCache

The distributed cache backend used for atomic operations.

serializer IBinarySerializer

The serializer for converting objects to/from binary format.

keyFactory IEntityStorageKeyFactory

The factory for generating standardized storage keys.

timeProvider System.TimeProvider

Provides the current time for seeding the request's absolute expiry.

Methods

DeviceAuthorizationStorage.RemoveAsync(string) Method

Removes a device authorization request from storage using its device code.

C#
public System.Threading.Tasks.Task RemoveAsync(string deviceCode);

Parameters

deviceCode System.String

The device code identifier.

Implements RemoveAsync(string)

Returns

System.Threading.Tasks.Task
A task that completes when the request is removed. Tidying the secondary user-code index is best-effort and is logged rather than raised: it is not what the caller asked for, and a store deciding otherwise must not become a fault where a grant error belongs. Removing the request itself is not guarded - that IS what was asked, so a refusal there raises.

DeviceAuthorizationStorage.StoreAsync(string, DeviceAuthorizationRequest, TimeSpan) Method

Stores a device authorization request with the specified device code.

C#
public System.Threading.Tasks.Task StoreAsync(string deviceCode, Abblix.Oidc.Server.Features.DeviceAuthorization.DeviceAuthorizationRequest request, System.TimeSpan expiresIn);

Parameters

deviceCode System.String

The unique device code identifier.

request DeviceAuthorizationRequest

The device authorization request to store.

expiresIn System.TimeSpan

The duration after which the stored request will expire.

Implements StoreAsync(string, DeviceAuthorizationRequest, TimeSpan)

Returns

System.Threading.Tasks.Task
A task that completes when the request is stored.

DeviceAuthorizationStorage.TryGetByDeviceCodeAsync(string) Method

Tries to retrieve a device authorization request by its device code. This is used by the client when polling the token endpoint.

C#
public System.Threading.Tasks.Task<Abblix.Oidc.Server.Features.DeviceAuthorization.DeviceAuthorizationRequest?> TryGetByDeviceCodeAsync(string deviceCode);

Parameters

deviceCode System.String

The device code identifier.

Implements TryGetByDeviceCodeAsync(string)

Returns

System.Threading.Tasks.Task<DeviceAuthorizationRequest>
A task that returns the device authorization request if found; otherwise, null.

DeviceAuthorizationStorage.TryGetByUserCodeAsync(string) Method

Tries to retrieve a device authorization request by its user code. This is used during user verification to look up the pending request.

C#
public System.Threading.Tasks.Task<System.Nullable<(string DeviceCode,Abblix.Oidc.Server.Features.DeviceAuthorization.DeviceAuthorizationRequest Request)>> TryGetByUserCodeAsync(string userCode);

Parameters

userCode System.String

The user-friendly verification code.

Implements TryGetByUserCodeAsync(string)

Returns

System.Threading.Tasks.Task<System.Nullable<<System.String,DeviceAuthorizationRequest>>>
A task that returns the device code and request if found; otherwise, null.

DeviceAuthorizationStorage.TryRemoveAsync(string, string) Method

Claims a device authorization request by device code, deciding presence and removing it in one protocol, so that a caller told it removed the request is the only caller that can be told so.

C#
public System.Threading.Tasks.Task<bool> TryRemoveAsync(string deviceCode, string userCode);

Parameters

deviceCode System.String

The device code identifying the authorization request to remove.

userCode System.String

The user code of THAT request, used to find its secondary index entry. Nothing here checks the two belong together - this method never reads the record - so a caller passing a code from a different request removes that other request's index entry instead, leaving a live request findable only by its device code.

Implements TryRemoveAsync(string, string)

Returns

System.Threading.Tasks.Task<System.Boolean>
A task that completes when the operation finishes, containing true when this caller removed the request AND still held the claim afterwards. False otherwise, which is wider than "another caller won or it was never there": the code can be consumed and the caller still told false, when the lock guarding the removal expires mid-protocol. The extension's remarks carry that condition.

The index cleanup that runs after the claim cannot change that answer either way. Removing the user-code index is a different question from whether this caller took the code, so a refusal is logged and the true stands. What the entry left behind still points at is not knowable here - this method never reads the record, so the user code it was handed need not belong to the request it removed - but that entry carries its own expiry either way.

Remarks

This method performs atomic removal of both the device code entry and its associated user code mapping. By accepting the userCode as a parameter, it avoids an additional cache read operation, since the caller already has this information from a previous fetch.

Use Case: This method is used in the Device Authorization Grant flow (RFC 8628) when exchanging an authorized device code for tokens. The claim keeps two token requests from both being told they took one device code, however many processes are polling. What it does not reach is a decision landing after the claim: that path re-reads the record and refuses, which leaves a window one store round trip wide rather than none - issues 194 and 435. The Atomicity note below says what the claim itself reaches.

Atomicity: Uses TryRemoveAsync(this IDistributedCache, string, Nullable<TimeSpan>, CancellationToken) which admits at most one caller through its lock-token protocol, and serializes redemptions of one device code in-process, which closes the one way a removal loses its winner to a competitor. What that does NOT give is a winner for every removal - the code can be consumed with nobody told they took it, and that needs neither a second caller nor a second node. The extension's own remarks carry the condition and name the store primitive that closes it. After a successful removal, cleans up the user code mapping.

DeviceAuthorizationStorage.UpdateAsync(string, DeviceAuthorizationRequest, TimeSpan) Method

Updates an existing device authorization request in storage, refreshing its cache entry with the caller-supplied remaining lifetime.

C#
public System.Threading.Tasks.Task UpdateAsync(string deviceCode, Abblix.Oidc.Server.Features.DeviceAuthorization.DeviceAuthorizationRequest request, System.TimeSpan expiresIn);

Parameters

deviceCode System.String

The device code identifier.

request DeviceAuthorizationRequest

The updated device authorization request.

expiresIn System.TimeSpan

The remaining lifetime to apply as the cache TTL. The caller derives it from the request's fixed expiry (RFC 8628 section 3.2) so that repeated polling cannot extend the code.

Implements UpdateAsync(string, DeviceAuthorizationRequest, TimeSpan)

Returns

System.Threading.Tasks.Task
A task that completes when the request is updated.