Saltar al contenido
Esta página aún no está traducida.

AuthorizationCodeService Class

Provides services for managing the lifecycle of OAuth 2.0 authorization codes. This service generates, stores, validates, and deletes authorization codes as part of the authorization code grant flow.

C#
public class AuthorizationCodeService : Abblix.Oidc.Server.Features.Storages.IAuthorizationCodeService

Inheritance System.Object → AuthorizationCodeService

Implements IAuthorizationCodeService

Constructors

AuthorizationCodeService(IAuthorizationCodeGenerator, IEntityStorage, IEntityStorageKeyFactory) Constructor

Provides services for managing the lifecycle of OAuth 2.0 authorization codes. This service generates, stores, validates, and deletes authorization codes as part of the authorization code grant flow.

C#
public AuthorizationCodeService(Abblix.Oidc.Server.Features.RandomGenerators.IAuthorizationCodeGenerator authorizationCodeGenerator, Abblix.Oidc.Server.Features.Storages.IEntityStorage storage, Abblix.Oidc.Server.Features.Storages.IEntityStorageKeyFactory keyFactory);

Parameters

authorizationCodeGenerator IAuthorizationCodeGenerator

The generator that creates unique authorization codes.

storage IEntityStorage

The storage mechanism for persisting and retrieving authorization codes and their associated data.

keyFactory IEntityStorageKeyFactory

The factory for generating standardized storage keys.

Methods

AuthorizationCodeService.AuthorizeByCodeAsync(string) Method

Validates and processes an authorization code, ensuring it is correct and has not expired or been used previously.

C#
public System.Threading.Tasks.Task<Abblix.Utils.Result<Abblix.Oidc.Server.Endpoints.Token.Interfaces.AuthorizedGrant,Abblix.Oidc.Server.Common.OidcError>> AuthorizeByCodeAsync(string authorizationCode);

Parameters

authorizationCode System.String

The authorization code to validate and process.

Implements AuthorizeByCodeAsync(string)

Returns

System.Threading.Tasks.Task<Abblix.Utils.Result<AuthorizedGrant,OidcError>>
A task that resolves to a Result<TSuccess,TFailure>, which indicates the outcome of the authorization attempt and contains any tokens issued.

AuthorizationCodeService.GenerateAuthorizationCodeAsync(AuthorizedGrant, TimeSpan) Method

Generates a unique authorization code for a given authorization grant result and client information. The client subsequently uses this code to request an access token.

C#
public System.Threading.Tasks.Task<string> GenerateAuthorizationCodeAsync(Abblix.Oidc.Server.Endpoints.Token.Interfaces.AuthorizedGrant authorizedGrant, System.TimeSpan authorizationCodeExpiresIn);

Parameters

authorizedGrant AuthorizedGrant

An object encapsulating the result of the authorization grant, including user authentication session and authorization context details.

authorizationCodeExpiresIn System.TimeSpan

Implements GenerateAuthorizationCodeAsync(AuthorizedGrant, TimeSpan)

Returns

System.Threading.Tasks.Task<System.String>
A task that resolves to the generated authorization code as a string.

AuthorizationCodeService.RemoveAuthorizationCodeAsync(string) Method

Atomically removes an authorization code from storage and returns the grant it held, in a single get-and-remove operation. This is how a code is claimed for redemption: it enforces the single-use guarantee against a race between two simultaneous redemptions of the same code (RFC 6749 section 4.1.2) - every other caller finds the code already gone and receives an invalid_grant failure.

One exception on a single node, and it is a loss rather than a duplication: a removal can end with NOBODY receiving the grant, when the claim expires mid-protocol. A store fault after the removal costs the grant the same way, and raises rather than answering.

Two callers both receiving it needs a SECOND NODE, and that holds of the storage this library ships rather than of the seam: the read and the removal happen under one hold of a per-key gate, so within one process a redeemer is never between them while another completes a take. A host substituting its own IEntityStorage owns that property, and a naive get-then-remove reopens the duplication on one node. Across processes the gate holds nothing either: the value is read before the claim is taken, the second caller is handed what it read rather than what it removed, and the reuse check sees no issued tokens. That is issue 435, and it needs a store primitive Microsoft.Extensions.Caching.Distributed.IDistributedCache does not expose.

C#
public System.Threading.Tasks.Task<Abblix.Utils.Result<Abblix.Oidc.Server.Endpoints.Token.Interfaces.AuthorizedGrant,Abblix.Oidc.Server.Common.OidcError>> RemoveAuthorizationCodeAsync(string authorizationCode);

Parameters

authorizationCode System.String

The authorization code to remove and claim.

Implements RemoveAuthorizationCodeAsync(string)

Returns

System.Threading.Tasks.Task<Abblix.Utils.Result<AuthorizedGrant,OidcError>>
The grant when this caller won the claim; an invalid_grantOidcError otherwise. Otherwise is wider than the obvious list - a concurrent request, an earlier consumption, an expiry, a code never issued - because the claim can also CONSUME the code and still refuse, when the lock guarding it expires mid-protocol. So a refusal does not prove another request took it, and looking for one is how that case is missed.

Remarks

A successfully claimed grant whose IssuedTokens is non-empty indicates the code was already used to issue tokens (a sequential reuse), which the caller treats as a reuse to be rejected and whose tokens are revoked.

AuthorizationCodeService.UpdateAuthorizationGrantAsync(string, AuthorizedGrant, TimeSpan) Method

Updates the authorization grant result based on a specific authorization code and client information. This method allows the authorization grant to be updated with new information or tokens as needed.

C#
public System.Threading.Tasks.Task UpdateAuthorizationGrantAsync(string authorizationCode, Abblix.Oidc.Server.Endpoints.Token.Interfaces.AuthorizedGrant authorizedGrant, System.TimeSpan authorizationCodeExpiresIn);

Parameters

authorizationCode System.String

The authorization code associated with the grant result to update.

authorizedGrant AuthorizedGrant

The updated authorization grant result containing the latest authentication and authorization details.

authorizationCodeExpiresIn System.TimeSpan

Implements UpdateAuthorizationGrantAsync(string, AuthorizedGrant, TimeSpan)

Returns

System.Threading.Tasks.Task
A task representing the asynchronous operation of updating the authorization grant result.