Aller au contenu
Cette page n'a pas encore été traduite.

PairwiseSubjectSettingsValidator Class

Fails loudly at startup when the configured seal key cannot key the pairwise seal, instead of letting the first pairwise token request answer 500.

C#
public sealed class PairwiseSubjectSettingsValidator : Microsoft.Extensions.Options.IValidateOptions<Abblix.Oidc.Server.Features.PairwiseIdentifiers.PairwiseSubjectSettings>

Inheritance System.Object → PairwiseSubjectSettingsValidator

Implements Microsoft.Extensions.Options.IValidateOptions<PairwiseSubjectSettings>

Remarks

The salt is the sole key material of the seal, and the two ways it goes wrong are both quiet. An absent key leaves the settings carrying null: required is a rule of the compiler, and the configuration binder assigns only the properties whose keys are present, so nothing is raised and nothing is set. A present but unusable key - not base64, or too short - is refused where it is assigned, but only for an instance somebody wrote in code.

Downstream, neither is loud either: SubjectTypeConverter treats settings it cannot use as pairwise not being configured, while discovery goes on advertising pairwise as a supported subject type. So a client registered for it is accepted and fails at the token endpoint.