DeviceAuthorizationStorage Class
Implements storage for device authorization requests as defined in RFC 8628. Stores requests by device_code (for client polling) with a secondary index by user_code (for user verification). Redemption of a device code goes through the cache's claim protocol, which narrows the window in which two token requests both claim one code rather than closing it.
public class DeviceAuthorizationStorage : Abblix.Oidc.Server.Features.DeviceAuthorization.Interfaces.IDeviceAuthorizationStorageInheritance System.Object → DeviceAuthorizationStorage
Implements IDeviceAuthorizationStorage
Constructors
DeviceAuthorizationStorage(ILogger<DeviceAuthorizationStorage>, IDistributedCache, IBinarySerializer, IEntityStorageKeyFactory, TimeProvider) Constructor
Implements storage for device authorization requests as defined in RFC 8628. Stores requests by device_code (for client polling) with a secondary index by user_code (for user verification). Redemption of a device code goes through the cache's claim protocol, which narrows the window in which two token requests both claim one code rather than closing it.
public DeviceAuthorizationStorage(Microsoft.Extensions.Logging.ILogger<Abblix.Oidc.Server.Features.DeviceAuthorization.DeviceAuthorizationStorage> logger, Microsoft.Extensions.Caching.Distributed.IDistributedCache cache, Abblix.Oidc.Server.Common.Interfaces.IBinarySerializer serializer, Abblix.Oidc.Server.Features.Storages.IEntityStorageKeyFactory keyFactory, System.TimeProvider timeProvider);Parameters
logger Microsoft.Extensions.Logging.ILogger<DeviceAuthorizationStorage>
Records a secondary-index entry left behind, which nothing else reports.
cache Microsoft.Extensions.Caching.Distributed.IDistributedCache
The distributed cache backend used for atomic operations.
serializer IBinarySerializer
The serializer for converting objects to/from binary format.
keyFactory IEntityStorageKeyFactory
The factory for generating standardized storage keys.
timeProvider System.TimeProvider
Provides the current time for seeding the request's absolute expiry.
Methods
DeviceAuthorizationStorage.RemoveAsync(string) Method
Removes a device authorization request from storage using its device code.
public System.Threading.Tasks.Task RemoveAsync(string deviceCode);Parameters
deviceCode System.String
The device code identifier.
Implements RemoveAsync(string)
Returns
System.Threading.Tasks.Task
A task that completes when the request is removed. Tidying the secondary user-code index is
best-effort and is logged rather than raised: it is not what the caller asked for, and a store
deciding otherwise must not become a fault where a grant error belongs. Removing the request
itself is not guarded - that IS what was asked, so a refusal there raises.
DeviceAuthorizationStorage.StoreAsync(string, DeviceAuthorizationRequest, TimeSpan) Method
Stores a device authorization request with the specified device code.
public System.Threading.Tasks.Task StoreAsync(string deviceCode, Abblix.Oidc.Server.Features.DeviceAuthorization.DeviceAuthorizationRequest request, System.TimeSpan expiresIn);Parameters
deviceCode System.String
The unique device code identifier.
request DeviceAuthorizationRequest
The device authorization request to store.
expiresIn System.TimeSpan
The duration after which the stored request will expire.
Implements StoreAsync(string, DeviceAuthorizationRequest, TimeSpan)
Returns
System.Threading.Tasks.Task
A task that completes when the request is stored.
DeviceAuthorizationStorage.TryGetByDeviceCodeAsync(string) Method
Tries to retrieve a device authorization request by its device code. This is used by the client when polling the token endpoint.
public System.Threading.Tasks.Task<Abblix.Oidc.Server.Features.DeviceAuthorization.DeviceAuthorizationRequest?> TryGetByDeviceCodeAsync(string deviceCode);Parameters
deviceCode System.String
The device code identifier.
Implements TryGetByDeviceCodeAsync(string)
Returns
System.Threading.Tasks.Task<DeviceAuthorizationRequest>
A task that returns the device authorization request if found; otherwise, null.
DeviceAuthorizationStorage.TryGetByUserCodeAsync(string) Method
Tries to retrieve a device authorization request by its user code. This is used during user verification to look up the pending request.
public System.Threading.Tasks.Task<System.Nullable<(string DeviceCode,Abblix.Oidc.Server.Features.DeviceAuthorization.DeviceAuthorizationRequest Request)>> TryGetByUserCodeAsync(string userCode);Parameters
userCode System.String
The user-friendly verification code.
Implements TryGetByUserCodeAsync(string)
Returns
System.Threading.Tasks.Task<System.Nullable<<System.String,DeviceAuthorizationRequest>>>
A task that returns the device code and request if found; otherwise, null.
DeviceAuthorizationStorage.TryRemoveAsync(string, string) Method
Claims a device authorization request by device code, deciding presence and removing it in one protocol, so that a caller told it removed the request is the only caller that can be told so.
public System.Threading.Tasks.Task<bool> TryRemoveAsync(string deviceCode, string userCode);Parameters
deviceCode System.String
The device code identifying the authorization request to remove.
userCode System.String
The user code of THAT request, used to find its secondary index entry. Nothing here checks the two belong together - this method never reads the record - so a caller passing a code from a different request removes that other request's index entry instead, leaving a live request findable only by its device code.
Implements TryRemoveAsync(string, string)
Returns
System.Threading.Tasks.Task<System.Boolean>
A task that completes when the operation finishes, containing true when this caller removed the
request AND still held the claim afterwards. False otherwise, which is wider than "another caller
won or it was never there": the code can be consumed and the caller still told false, when the lock
guarding the removal expires mid-protocol. The extension's remarks carry that condition.
The index cleanup that runs after the claim cannot change that answer either way. Removing the user-code index is a different question from whether this caller took the code, so a refusal is logged and the true stands. What the entry left behind still points at is not knowable here - this method never reads the record, so the user code it was handed need not belong to the request it removed - but that entry carries its own expiry either way.
Remarks
This method performs atomic removal of both the device code entry and its associated user code mapping. By accepting the userCode as a parameter, it avoids an additional cache read operation, since the caller already has this information from a previous fetch.
Use Case: This method is used in the Device Authorization Grant flow (RFC 8628) when exchanging an authorized device code for tokens. The claim keeps two token requests from both being told they took one device code, however many processes are polling. What it does not reach is a decision landing after the claim: that path re-reads the record and refuses, which leaves a window one store round trip wide rather than none - issues 194 and 435. The Atomicity note below says what the claim itself reaches.
Atomicity: Uses TryRemoveAsync(this IDistributedCache, string, Nullable<TimeSpan>, CancellationToken) which admits at most one caller through its lock-token protocol, and serializes redemptions of one device code in-process, which closes the one way a removal loses its winner to a competitor. What that does NOT give is a winner for every removal - the code can be consumed with nobody told they took it, and that needs neither a second caller nor a second node. The extension's own remarks carry the condition and name the store primitive that closes it. After a successful removal, cleans up the user code mapping.
DeviceAuthorizationStorage.UpdateAsync(string, DeviceAuthorizationRequest, TimeSpan) Method
Updates an existing device authorization request in storage, refreshing its cache entry with the caller-supplied remaining lifetime.
public System.Threading.Tasks.Task UpdateAsync(string deviceCode, Abblix.Oidc.Server.Features.DeviceAuthorization.DeviceAuthorizationRequest request, System.TimeSpan expiresIn);Parameters
deviceCode System.String
The device code identifier.
request DeviceAuthorizationRequest
The updated device authorization request.
expiresIn System.TimeSpan
The remaining lifetime to apply as the cache TTL. The caller derives it from the request's fixed expiry (RFC 8628 section 3.2) so that repeated polling cannot extend the code.
Implements UpdateAsync(string, DeviceAuthorizationRequest, TimeSpan)
Returns
System.Threading.Tasks.Task
A task that completes when the request is updated.