Aller au contenu
Cette page n'a pas encore été traduite.

JwtTypes Class

The typ values this server mints for its own token kinds, and the refusal decision that sees them. The specification-fixed vocabulary lives in the JWT core's JsonWebTokenTypes, shared by every package on the core; what stays here is what only this product can own - its vendor-tree values - plus the combined known set the two vocabularies form together.

C#
public static class JwtTypes

Inheritance System.Object → JwtTypes

Remarks

RFC 6838 Section 3.2 is where the prefix comes from: the vendor tree "is used for media types associated with publicly available products", and its registrations "will be distinguished by the leading facet vnd.". Names without it belong to the standards tree, where a future registration of the same word would collide with ours - and, worse for a reader, a name sitting there looks exactly as authoritative as one that was actually standardised.

Changing a prefixed value is possible but not free: it changes what an already-issued token looks like, so tokens minted before the change stop being recognised.

Fields

JwtTypes.AccessToken Field

The "AccessToken" JWT type per RFC 9068, fixed by the specification.

C#
public const string AccessToken = "at+jwt";

Field Value

System.String

JwtTypes.DPoPProof Field

The "DPoP proof" JWT type per RFC 9449 §4.2, fixed by the specification.

C#
public const string DPoPProof = "dpop+jwt";

Field Value

System.String

JwtTypes.InitialAccessToken Field

The "InitialAccessToken" JWT type is used to authorize calls to the client registration endpoint per RFC 7591 Section 3.

C#
public const string InitialAccessToken = "vnd.abblix.iat+jwt";

Field Value

System.String

Remarks

Not replaceable by AccessToken, and here the type is load-bearing on its own. Beyond it, the validator asks only for a non-empty subject that has not been revoked, so sharing a type with the access token would let any access token this server issued register clients.

JwtTypes.Jwt Field

Standard JSON Web Token type. Per RFC 7519 Section 5.1, this is the recommended value for the 'typ' header parameter.

C#
public const string Jwt = "JWT";

Field Value

System.String

JwtTypes.LogoutToken Field

The "LogoutToken" JWT type per OpenID Connect Back-Channel Logout, fixed by the specification.

C#
public const string LogoutToken = "logout+jwt";

Field Value

System.String

JwtTypes.RefreshToken Field

The "RefreshToken" JWT type is used to represent refresh tokens, which allow obtaining new access tokens without reauthentication.

C#
public const string RefreshToken = "vnd.abblix.rt+jwt";

Field Value

System.String

Remarks

Not replaceable by AccessToken, and the reason is a protection rather than a preference. A refresh token carries the resources of its grant in the audience claim, exactly as the access token of that grant does, so with a shared type nothing would separate the two and a resource server presented with a refresh token would have no ground to refuse it. There is also nowhere standard to move to: the IANA media types registry holds no entry for a refresh token, which follows from RFC 6749 Section 1.5 making it a value "intended for use only with authorization servers".

JwtTypes.RegistrationAccessToken Field

The "RegistrationAccessToken" JWT type is used in OAuth 2.0 Dynamic Client Registration for securely registering clients.

C#
public const string RegistrationAccessToken = "vnd.abblix.dcr+jwt";

Field Value

System.String

Remarks

Not replaceable by AccessToken. Its validator does ask for more - the subject must name the client being managed, and the identifier must match the one that client records - but the second of those is enforced only where a record exists, which leaves a statically configured client defended by the subject alone. An access token issued for the client itself carries that same subject, so the type is what keeps the two apart. See also InitialAccessToken, which has nothing else at all.

JwtTypes.TokenIntrospection Field

The "token introspection response" JWT type per RFC 9701 §5, fixed by the specification.

C#
public const string TokenIntrospection = "token-introspection+jwt";

Field Value

System.String

Methods

JwtTypes.IsPermitted(string, string[]) Method

Reports whether a typ is one this position permits, over the combined vocabulary of the core registry and this server's vendor values. The decision itself - refusal by kind, with an absent, generic or unfamiliar value passing untouched - is IsPermitted(string, IReadOnlyList<string>, string[]); see its remarks for why the refused side is enumerated rather than the accepted one.

C#
public static bool IsPermitted(string? tokenType, params string[] permittedTypes);

Parameters

tokenType System.String

The typ header parameter of the incoming JWT, which may be absent.

permittedTypes System.String[]

The types this position permits. Pass none where the JWT that belongs there carries no typ at all, as an ID token does - then every known type is out of place.

Returns

System.Boolean
true for an absent, generic or unfamiliar value and for any of permittedTypes; false only for a known type that is not among them.