Saltar al contenido
Esta página aún no está traducida.

SecureHttpFetcherExtensions Class

Provides reusable functionality for fetching JSON Web Key Sets (JWKS) from remote URIs with SSRF protection and consistent error handling.

C#
public static class SecureHttpFetcherExtensions

Inheritance System.Object → SecureHttpFetcherExtensions

Methods

SecureHttpFetcherExtensions.FetchKeysAsync(this ISecureHttpFetcher, Uri, ILogger, string, string) Method

Fetches JSON Web Keys from a JWKS URI with SSRF protection and optional filtering.

C#
public static System.Collections.Generic.IAsyncEnumerable<Abblix.Jwt.JsonWebKey> FetchKeysAsync(this Abblix.Oidc.Server.Features.SecureHttpFetch.ISecureHttpFetcher secureFetcher, System.Uri jwksUri, Microsoft.Extensions.Logging.ILogger logger, string entityId, string entityType);

Parameters

secureFetcher ISecureHttpFetcher

HTTP fetcher with SSRF protection and caching.

jwksUri System.Uri

The URI to fetch the JWKS from.

logger Microsoft.Extensions.Logging.ILogger

Logger for recording fetch operations and errors.

entityId System.String

The identifier of the entity (client ID or issuer) for logging.

entityType System.String

The type of entity (e.g., "client" or "issuer") for logging.

Returns

System.Collections.Generic.IAsyncEnumerable<JsonWebKey>
An async enumerable of JSON Web Keys from the JWKS endpoint. Returns empty if fetching fails or the JWKS is invalid.

SecureHttpFetcherExtensions.ResolveKeysAsync(this IServiceProvider, JsonWebKeySet, Uri, ILogger, string, string) Method

Resolves the keys a party publishes, in the two forms a party may publish them: inline in its registration, and at a JWKS URI. Both may be present, and the inline keys come first.

C#
public static System.Collections.Generic.IAsyncEnumerable<Abblix.Jwt.JsonWebKey> ResolveKeysAsync(this System.IServiceProvider serviceProvider, Abblix.Jwt.JsonWebKeySet? jwks, System.Uri? jwksUri, Microsoft.Extensions.Logging.ILogger logger, string entityId, string entityType);

Parameters

serviceProvider System.IServiceProvider

Used to resolve ISecureHttpFetcher, which is scoped while the providers calling this are not, so a scope is created per call rather than held.

jwks JsonWebKeySet

The key set held in the party's own registration, if any.

jwksUri System.Uri

The URI the party publishes its key set at, if any.

logger Microsoft.Extensions.Logging.ILogger

Logger for recording fetch operations and errors.

entityId System.String

The identifier of the party, for logging.

entityType System.String

What kind of party it is. Must be a value from KeySetOwners: besides labelling the log, it is the service key under which this consumer's cached fetcher is registered, so the same value selects the cache lifetime that consumer was given.

Returns

System.Collections.Generic.IAsyncEnumerable<JsonWebKey>
The inline keys followed by the fetched ones. Empty when the party declares neither.

Remarks

The fetch itself is SSRF-protected and cached by the decorators around ISecureHttpFetcher, so a caller gets both without arranging either.