Aller au contenu
Cette page n'a pas encore été traduite.

SubjectTypeValidator Class

Validates the OIDC Core Section 8 subject_type metadata and computes the pairwise sector identifier. When pairwise is requested, a supplied sector_identifier_uri (HTTPS) is dereferenced and every URI the registration is required to have listed there is checked against its contents; otherwise the host is taken from the registered redirect URIs, which must agree on one (OIDC Core Section 8.1). A backchannel client that registered NO redirect URI takes its host instead from the URI CIBA Core 1.0 Section 4 puts in their place - the jwks_uri in poll and ping, the backchannel_client_notification_endpoint in push. Registering both is allowed and they need not agree: the redirect URIs decide, and the backchannel URI is only ever the sector of a client that has none. The resolved host is stored on the context for later persistence.

C#
public class SubjectTypeValidator : Abblix.Oidc.Server.Endpoints.DynamicClientManagement.Validation.IClientRegistrationContextValidator

Inheritance System.Object → SubjectTypeValidator

Implements IClientRegistrationContextValidator

Constructors

SubjectTypeValidator(ILogger<SubjectTypeValidator>, ISecureHttpFetcher) Constructor

Validates the OIDC Core Section 8 subject_type metadata and computes the pairwise sector identifier. When pairwise is requested, a supplied sector_identifier_uri (HTTPS) is dereferenced and every URI the registration is required to have listed there is checked against its contents; otherwise the host is taken from the registered redirect URIs, which must agree on one (OIDC Core Section 8.1). A backchannel client that registered NO redirect URI takes its host instead from the URI CIBA Core 1.0 Section 4 puts in their place - the jwks_uri in poll and ping, the backchannel_client_notification_endpoint in push. Registering both is allowed and they need not agree: the redirect URIs decide, and the backchannel URI is only ever the sector of a client that has none. The resolved host is stored on the context for later persistence.

C#
public SubjectTypeValidator(Microsoft.Extensions.Logging.ILogger<Abblix.Oidc.Server.Endpoints.DynamicClientManagement.Validation.SubjectTypeValidator> logger, Abblix.Oidc.Server.Features.SecureHttpFetch.ISecureHttpFetcher secureHttpFetcher);

Parameters

logger Microsoft.Extensions.Logging.ILogger<SubjectTypeValidator>

Logger used for warnings about sector-identifier mismatches.

secureHttpFetcher ISecureHttpFetcher

SSRF-protected fetcher for the sector identifier document.

Methods

SubjectTypeValidator.ValidateAsync(ClientRegistrationValidationContext) Method

Validates the slice of registration metadata this implementation owns. May mutate ClientRegistrationValidationContext with derived values (for example the resolved sector identifier).

C#
public System.Threading.Tasks.Task<Abblix.Oidc.Server.Common.OidcError?> ValidateAsync(Abblix.Oidc.Server.Endpoints.DynamicClientManagement.Validation.ClientRegistrationValidationContext context);

Parameters

context ClientRegistrationValidationContext

The shared validation context for the current request.

Implements ValidateAsync(ClientRegistrationValidationContext)

Returns

System.Threading.Tasks.Task<OidcError>
An OidcError describing the rejection, or null when valid.