TokenStatusValidatorDecorator Class
Adds revocation checking to an existing IJsonWebTokenValidator: a token that has been rotated, whose grant family was killed, or that a subject- or session-level cutoff reaches is refused after the inner validator has accepted it.
public class TokenStatusValidatorDecorator : Abblix.Jwt.IJsonWebTokenValidatorInheritance System.Object → TokenStatusValidatorDecorator
Implements IJsonWebTokenValidator
Remarks
The two halves come from different stores and answer different questions, which is why the cutoff lives behind IRevocationCutoffChecker rather than here: this type asks what is recorded about one token, and that one asks what is recorded about the principal behind it.
Constructors
TokenStatusValidatorDecorator(ITokenRegistry, IRevocationCutoffChecker, IJsonWebTokenValidator) Constructor
Adds revocation checking to an existing IJsonWebTokenValidator: a token that has been rotated, whose grant family was killed, or that a subject- or session-level cutoff reaches is refused after the inner validator has accepted it.
public TokenStatusValidatorDecorator(Abblix.Oidc.Server.Features.Storages.ITokenRegistry tokenRegistry, Abblix.Oidc.Server.Features.Tokens.Revocation.IRevocationCutoffChecker cutoffChecker, Abblix.Jwt.IJsonWebTokenValidator innerValidator);Parameters
tokenRegistry ITokenRegistry
The token registry used to check token status.
cutoffChecker IRevocationCutoffChecker
Decides whether a revocation cutoff reaches this token.
innerValidator IJsonWebTokenValidator
The inner validator for initial token validation.
Remarks
The two halves come from different stores and answer different questions, which is why the cutoff lives behind IRevocationCutoffChecker rather than here: this type asks what is recorded about one token, and that one asks what is recorded about the principal behind it.
Properties
TokenStatusValidatorDecorator.EncryptionAlgorithmsSupported Property
Forwards the JWE key-management algorithms accepted by the inner validator; revocation checking does not influence which encryption algorithms are supported.
public System.Collections.Generic.IEnumerable<string> EncryptionAlgorithmsSupported { get; }Implements EncryptionAlgorithmsSupported
Property Value
System.Collections.Generic.IEnumerable<System.String>
TokenStatusValidatorDecorator.EncryptionMethodsSupported Property
Forwards the JWE content-encryption algorithms accepted by the inner validator; revocation checking does not influence which encryption algorithms are supported.
public System.Collections.Generic.IEnumerable<string> EncryptionMethodsSupported { get; }Implements EncryptionMethodsSupported
Property Value
System.Collections.Generic.IEnumerable<System.String>
TokenStatusValidatorDecorator.SigningAlgorithmsSupported Property
Forwards the set of JWS signing algorithms accepted by the inner validator (RFC 7518 §3.1
names such as RS256, PS256, ES256); revocation checking does not
influence which algorithms are supported.
public System.Collections.Generic.IEnumerable<string> SigningAlgorithmsSupported { get; }Implements SigningAlgorithmsSupported
Property Value
System.Collections.Generic.IEnumerable<System.String>
Methods
TokenStatusValidatorDecorator.ValidateAsync(string, ValidationParameters) Method
Validates a JSON Web Token (JWT) and checks its revocation status.
public System.Threading.Tasks.Task<Abblix.Utils.Result<Abblix.Jwt.JsonWebToken,Abblix.Jwt.JwtValidationError>> ValidateAsync(string jwt, Abblix.Jwt.ValidationParameters parameters);Parameters
jwt System.String
The JWT to be validated.
parameters ValidationParameters
Validation parameters to use during validation.
Implements ValidateAsync(string, ValidationParameters)
Returns
System.Threading.Tasks.Task<Abblix.Utils.Result<JsonWebToken,JwtValidationError>>
A Result containing either a validated JsonWebToken or a JwtValidationError.
If the token is revoked or already used, it returns a JwtValidationError.
Otherwise, it returns the result from the inner validator.