Aller au contenu
Cette page n'a pas encore été traduite.

JwtBearerOptions Class

Configuration options for JWT Bearer grant type (RFC 7523). Defines trusted external identity providers whose JWT assertions can be exchanged for access tokens.

C#
public record JwtBearerOptions : System.IEquatable<Abblix.Oidc.Server.Common.Configuration.JwtBearerOptions>

Inheritance System.Object → JwtBearerOptions

Implements System.IEquatable<JwtBearerOptions>

Properties

JwtBearerOptions.AllowedTokenTypes Property

Allowed values for the 'typ' (type) header in JWT assertions. When not empty, JWTs must have a typ header matching one of these values. Common values include "JWT" and "at+jwt". Default is empty (typ header validation disabled).

C#
public string[] AllowedTokenTypes { get; set; }

Property Value

System.String[]

Remarks

While RFC 7523 does not mandate typ header validation, validating it prevents token confusion attacks in multi-token environments where different token types (access tokens, ID tokens, assertions) may coexist. Set to ["JWT"] or ["at+jwt"] based on your token ecosystem requirements.

JwtBearerOptions.ClockSkew Property

The clock skew tolerance applied to a bearer assertion, in both directions. Absent unless this deployment sets one, which leaves the answer to the security profile in force.

C#
public System.Nullable<System.TimeSpan> ClockSkew { get; set; }

Property Value

System.Nullable<System.TimeSpan>

Remarks

An assertion arrives from an issuer whose clock this server does not run, which is why the tolerance a profile-free deployment gets here is looser than the one applied to tokens minted closer to home. RFC 7523 Section 3 allows for clock skew without naming a bound, so the value a profile-free deployment receives is this server's choice rather than the specification's. FAPI 2.0 Security Profile section 5.3.2.1 makes a tighter choice of its own, and separately names a furthest point - which is a ceiling on whatever is set here rather than a value this resolves to.

Absent rather than the default written here, because the two are not the same fact. A number nobody chose cannot be told apart from one a deployment set on purpose, so a guard refusing a value a profile will not honour would refuse the default as well - failing every FAPI deployment at startup over a value it never touched. Absence says "decide for me"; a value says "I mean this", and only the second is worth refusing.

It bounds two things, both about the same clock: how far a timestamp may sit either side of this server's, and how much older than MaxJwtAge an assertion may be.

JwtBearerOptions.JwksCacheDuration Property

The duration for which JWKS (JSON Web Key Sets) are cached before being refreshed. Reduces network calls and improves performance while ensuring keys are periodically updated. Default is 1 hour.

C#
public System.TimeSpan JwksCacheDuration { get; set; }

Property Value

System.TimeSpan

JwtBearerOptions.MaxJwtAge Property

Maximum age of JWT assertions based on the 'iat' (issued at) claim. JWTs issued more than this duration in the past will be rejected. Set to null to disable this validation. Default is 10 minutes.

C#
public System.Nullable<System.TimeSpan> MaxJwtAge { get; set; }

Property Value

System.Nullable<System.TimeSpan>

Remarks

Per RFC 7523 Section 3: "The authorization server MAY reject JWTs with an 'iat' claim value that is unreasonably far in the past." This provides defense-in-depth against replay attacks, especially useful when RequireJti is disabled or when the JTI cache has gaps.

JwtBearerOptions.MaxJwtSize Property

Maximum allowed size for JWT assertions in characters. Prevents denial-of-service attacks via excessively large JWTs. Default is 8192 (8KB).

C#
public int MaxJwtSize { get; set; }

Property Value

System.Int32

JwtBearerOptions.RequireJti Property

Indicates whether the 'jti' (JWT ID) claim is required for replay protection. When enabled, JWTs without a jti claim will be rejected to prevent replay attacks. Default is true. RFC 7523 Section 6 leaves replay protection optional and at the implementation's discretion, so refusing an assertion without a jti is this server's choice rather than a requirement it inherits.

C#
public bool RequireJti { get; set; }

Property Value

System.Boolean

JwtBearerOptions.StrictAudienceValidation Property

When true, the JWT audience claim must exactly match the token endpoint URL per RFC 7523 Section 3. When false, the application base URI is also accepted for compatibility with common implementations. Default is true for strict RFC 7523 compliance and security.

C#
public bool StrictAudienceValidation { get; set; }

Property Value

System.Boolean

Remarks

Set to false only if you have legacy clients that use the application base URI as audience. Accepting the base URI widens the attack surface as JWTs intended for other endpoints on the same server could potentially be misused.

JwtBearerOptions.TrustedIssuers Property

Collection of trusted issuers configuration for JWT Bearer grant type. Each entry defines an external identity provider that is trusted to issue JWT assertions that can be exchanged for access tokens at this authorization server.

C#
public System.Collections.Generic.IEnumerable<Abblix.Oidc.Server.Common.Configuration.TrustedIssuer> TrustedIssuers { get; set; }

Property Value

System.Collections.Generic.IEnumerable<TrustedIssuer>

Remarks

Use cases include: - Service-to-service authentication with pre-existing trust relationships - Token exchange between federated identity providers - Cross-domain single sign-on (SSO) scenarios - API-to-API communication with JWT from external identity provider

Methods

JwtBearerOptions.ResolveClockSkew(ClientSecurityProfile) Method

The tolerance actually applied to a bearer assertion: what this deployment set, or what the profile in force supplies.

C#
public Abblix.Jwt.ClockSkew ResolveClockSkew(Abblix.Oidc.Server.Common.Constants.ClientSecurityProfile profile);

Parameters

profile ClientSecurityProfile

The security profile this deployment is held to.

Returns

ClockSkew

Remarks

Every reader of the setting goes through here. Three readers each applying their own fallback are three chances to disagree about what an absent value meant, and the disagreement would surface as one check refusing an assertion another had just accepted.

JwtBearerOptions.ResolveClockSkew(SecurityProfileRequirements) Method

The same, over a bundle the caller has already resolved - which a per-client caller has, since the client's own profile decides for it.

C#
public Abblix.Jwt.ClockSkew ResolveClockSkew(Abblix.Oidc.Server.Features.ClientInformation.SecurityProfileRequirements requirements);

Parameters

requirements SecurityProfileRequirements

The control bundle in force.

Returns

ClockSkew