PingModeGrantProcessor Class
Handles CIBA ping mode token retrieval at the token endpoint. In ping mode, the server notifies the client, then the client makes a single token request. The auth_req_id is single-use - CIBA Core 1.0 Section 10.1.1: "Once redeemed for a successful token response, the auth_req_id value that was used is no longer valid" - so the grant is removed from storage on retrieval, identically to poll mode, whose token response the same section defines.
public class PingModeGrantProcessor : Abblix.Oidc.Server.Features.BackChannelAuthentication.Interfaces.IBackChannelGrantProcessorInheritance System.Object → PingModeGrantProcessor
Implements IBackChannelGrantProcessor
Constructors
PingModeGrantProcessor(IBackChannelRequestStorage) Constructor
Handles CIBA ping mode token retrieval at the token endpoint. In ping mode, the server notifies the client, then the client makes a single token request. The auth_req_id is single-use - CIBA Core 1.0 Section 10.1.1: "Once redeemed for a successful token response, the auth_req_id value that was used is no longer valid" - so the grant is removed from storage on retrieval, identically to poll mode, whose token response the same section defines.
public PingModeGrantProcessor(Abblix.Oidc.Server.Features.BackChannelAuthentication.Interfaces.IBackChannelRequestStorage storage);Parameters
storage IBackChannelRequestStorage
Storage for backchannel authentication requests.
Methods
PingModeGrantProcessor.ProcessAuthenticatedRequestAsync(string, BackChannelAuthenticationRequest) Method
Removes the authentication request from storage under the store's per-key gate and returns its
authorized grant.
Because the auth_req_id can be used only once (CIBA Core 1.0 Section 10.1.1), a retrieval that
does not come back with the request is rejected with invalid_grant rather than re-issuing
tokens. Which is the right answer to give the caller, and not a diagnosis: the request comes back
only when this caller ran the protocol to the end with its own claim still in the store, and
every way short of that is one answer.
A store call that fails after the removal produces neither - it raises, and the caller is handed
an exception instead of a result.
public System.Threading.Tasks.Task<Abblix.Utils.Result<Abblix.Oidc.Server.Endpoints.Token.Interfaces.AuthorizedGrant,Abblix.Oidc.Server.Common.OidcError>> ProcessAuthenticatedRequestAsync(string authenticationRequestId, Abblix.Oidc.Server.Features.BackChannelAuthentication.BackChannelAuthenticationRequest request);Parameters
authenticationRequestId System.String
request BackChannelAuthenticationRequest
Implements ProcessAuthenticatedRequestAsync(string, BackChannelAuthenticationRequest)
Returns
System.Threading.Tasks.Task<Abblix.Utils.Result<AuthorizedGrant,OidcError>>
PingModeGrantProcessor.ValidateTokenEndpointAccess() Method
Ping mode clients are allowed to call the token endpoint after the ping notification arrives,
so this always returns null (no error).
public Abblix.Oidc.Server.Common.OidcError? ValidateTokenEndpointAccess();Implements ValidateTokenEndpointAccess()