BackChannelAuthenticationRequest Class
Represents a backchannel authentication request as part of the Client-Initiated Backchannel Authentication (CIBA) protocol. This request facilitates the authentication of users without requiring immediate interaction with their devices, allowing for a more flexible and user-friendly authentication experience.
public record BackChannelAuthenticationRequest : System.IEquatable<Abblix.Oidc.Server.Features.BackChannelAuthentication.BackChannelAuthenticationRequest>Inheritance System.Object → BackChannelAuthenticationRequest
Implements System.IEquatable<BackChannelAuthenticationRequest>
Constructors
BackChannelAuthenticationRequest(AuthorizedGrant, DateTimeOffset) Constructor
Represents a backchannel authentication request as part of the Client-Initiated Backchannel Authentication (CIBA) protocol. This request facilitates the authentication of users without requiring immediate interaction with their devices, allowing for a more flexible and user-friendly authentication experience.
public BackChannelAuthenticationRequest(Abblix.Oidc.Server.Endpoints.Token.Interfaces.AuthorizedGrant AuthorizedGrant, System.DateTimeOffset ExpiresAt);Parameters
AuthorizedGrant AuthorizedGrant
The authorized grant associated with this authentication request, containing details about the user's authorization context.
ExpiresAt System.DateTimeOffset
The absolute time when this backchannel authentication request expires.
Properties
BackChannelAuthenticationRequest.AuthorizedGrant Property
The authorized grant associated with this authentication request, containing details about the user's authorization context.
public Abblix.Oidc.Server.Endpoints.Token.Interfaces.AuthorizedGrant AuthorizedGrant { get; init; }Property Value
BackChannelAuthenticationRequest.ClientNotificationEndpoint Property
The client notification endpoint for ping mode. Populated from client configuration when ping mode is used.
public System.Uri? ClientNotificationEndpoint { get; set; }Property Value
BackChannelAuthenticationRequest.ClientNotificationToken Property
The client notification token for ping mode. Provided by the client in the authentication request for secure notification delivery.
public string? ClientNotificationToken { get; set; }Property Value
BackChannelAuthenticationRequest.ExpiresAt Property
The absolute time when this backchannel authentication request expires.
public System.DateTimeOffset ExpiresAt { get; init; }Property Value
BackChannelAuthenticationRequest.NextPollAt Property
Specifies the next time the client should poll for updates regarding the authentication request. This helps manage the timing of polling requests efficiently.
public System.Nullable<System.DateTimeOffset> NextPollAt { get; set; }Property Value
System.Nullable<System.DateTimeOffset>
BackChannelAuthenticationRequest.RequestedAuthorizationDetails Property
The RFC 9396 authorization_details the client asked for, as the request-time validators
left them. EMPTY when the request carried none; null only on a request stored before this
field existed, which is why the two are not the same answer.
public System.Text.Json.Nodes.JsonArray? RequestedAuthorizationDetails { get; set; }Property Value
System.Text.Json.Nodes.JsonArray
Remarks
Kept apart from the array on AuthorizedGrant, which is what will be issued. The two are the same until the end user answers: a host whose device UI let them approve part of the request replaces the grant's context before completing, and this is what that answer is judged against.
Recorded rather than derived, for the reason RequestedSubjects is: in a decoupled flow the answer arrives long after the request, through CompleteAsync(string, BackChannelAuthenticationRequest, TimeSpan), and by then the only copy of what was asked for would be the one the host has just overwritten.
BackChannelAuthenticationRequest.RequestedSubjects Property
The end users the request will accept, spelled as the requesting client sees them, or null
when it named nobody in particular. An empty array accepts nobody.
public string[]? RequestedSubjects { get; set; }Property Value
Remarks
Recorded here rather than compared once and discarded, because in a decoupled flow the end user authenticates long after the request was made: the session that answers it arrives through CompleteAsync(string, BackChannelAuthenticationRequest, TimeSpan), and OpenID Connect Core 1.0 Section 3.1.2.2 forbids answering for anyone else. Without this the comparison would have nothing left to compare against by the time there is a session to judge.
A set rather than a name, because the two parameters that can name an end user do not agree on the
shape: an id_token_hint names one, and a claims request may list several it would
accept. Section 3.1.2.2 puts both under a single requirement, so both land here.
BackChannelAuthenticationRequest.Status Property
Indicates the current status of the backchannel authentication request. Defaults to Pending, reflecting that the request has not yet been resolved.
public Abblix.Oidc.Server.Features.BackChannelAuthentication.BackChannelAuthenticationStatus Status { get; set; }