PollModeGrantProcessor Class
Handles CIBA poll mode token retrieval at the token endpoint. In poll mode, clients repeatedly poll until authentication completes. The stored request is claimed on retrieval - read and removed in one protocol - so that a poll told it took the request is the only poll that can be told so. That narrows the window in which two polls both issue rather than closing it; the method below says what its refusal covers.
public class PollModeGrantProcessor : Abblix.Oidc.Server.Features.BackChannelAuthentication.Interfaces.IBackChannelGrantProcessorInheritance System.Object → PollModeGrantProcessor
Implements IBackChannelGrantProcessor
Constructors
PollModeGrantProcessor(IBackChannelRequestStorage) Constructor
Handles CIBA poll mode token retrieval at the token endpoint. In poll mode, clients repeatedly poll until authentication completes. The stored request is claimed on retrieval - read and removed in one protocol - so that a poll told it took the request is the only poll that can be told so. That narrows the window in which two polls both issue rather than closing it; the method below says what its refusal covers.
public PollModeGrantProcessor(Abblix.Oidc.Server.Features.BackChannelAuthentication.Interfaces.IBackChannelRequestStorage storage);Parameters
storage IBackChannelRequestStorage
Storage for backchannel authentication requests.
Methods
PollModeGrantProcessor.ProcessAuthenticatedRequestAsync(string, BackChannelAuthenticationRequest) Method
Removes the authentication request from storage through the store's claim protocol and returns its
authorized grant.
A removal that does not come back with the request is answered invalid_grant rather than
re-issuing tokens. That is the right answer and not a diagnosis: the request comes back only when
this caller ran the protocol to the end with its own claim still in the store, and every way short
of that is one answer. A store fault after the removal is not among them at all - it raises past
this method.
public System.Threading.Tasks.Task<Abblix.Utils.Result<Abblix.Oidc.Server.Endpoints.Token.Interfaces.AuthorizedGrant,Abblix.Oidc.Server.Common.OidcError>> ProcessAuthenticatedRequestAsync(string authenticationRequestId, Abblix.Oidc.Server.Features.BackChannelAuthentication.BackChannelAuthenticationRequest request);Parameters
authenticationRequestId System.String
request BackChannelAuthenticationRequest
Implements ProcessAuthenticatedRequestAsync(string, BackChannelAuthenticationRequest)
Returns
System.Threading.Tasks.Task<Abblix.Utils.Result<AuthorizedGrant,OidcError>>
PollModeGrantProcessor.ValidateTokenEndpointAccess() Method
Poll mode clients are expected to poll the token endpoint, so this always returns null (no error).
public Abblix.Oidc.Server.Common.OidcError? ValidateTokenEndpointAccess();Implements ValidateTokenEndpointAccess()