AuthorizationCodeService Class
Provides services for managing the lifecycle of OAuth 2.0 authorization codes. This service generates, stores, validates, and deletes authorization codes as part of the authorization code grant flow.
public class AuthorizationCodeService : Abblix.Oidc.Server.Features.Storages.IAuthorizationCodeServiceInheritance System.Object → AuthorizationCodeService
Implements IAuthorizationCodeService
Constructors
AuthorizationCodeService(IAuthorizationCodeGenerator, IEntityStorage, IEntityStorageKeyFactory) Constructor
Provides services for managing the lifecycle of OAuth 2.0 authorization codes. This service generates, stores, validates, and deletes authorization codes as part of the authorization code grant flow.
public AuthorizationCodeService(Abblix.Oidc.Server.Features.RandomGenerators.IAuthorizationCodeGenerator authorizationCodeGenerator, Abblix.Oidc.Server.Features.Storages.IEntityStorage storage, Abblix.Oidc.Server.Features.Storages.IEntityStorageKeyFactory keyFactory);Parameters
authorizationCodeGenerator IAuthorizationCodeGenerator
The generator that creates unique authorization codes.
storage IEntityStorage
The storage mechanism for persisting and retrieving authorization codes and their associated data.
keyFactory IEntityStorageKeyFactory
The factory for generating standardized storage keys.
Methods
AuthorizationCodeService.AuthorizeByCodeAsync(string) Method
Validates and processes an authorization code, ensuring it is correct and has not expired or been used previously.
public System.Threading.Tasks.Task<Abblix.Utils.Result<Abblix.Oidc.Server.Endpoints.Token.Interfaces.AuthorizedGrant,Abblix.Oidc.Server.Common.OidcError>> AuthorizeByCodeAsync(string authorizationCode);Parameters
authorizationCode System.String
The authorization code to validate and process.
Implements AuthorizeByCodeAsync(string)
Returns
System.Threading.Tasks.Task<Abblix.Utils.Result<AuthorizedGrant,OidcError>>
A task that resolves to a Result<TSuccess,TFailure>, which indicates the outcome of
the authorization attempt and contains any tokens issued.
AuthorizationCodeService.GenerateAuthorizationCodeAsync(AuthorizedGrant, TimeSpan) Method
Generates a unique authorization code for a given authorization grant result and client information. The client subsequently uses this code to request an access token.
public System.Threading.Tasks.Task<string> GenerateAuthorizationCodeAsync(Abblix.Oidc.Server.Endpoints.Token.Interfaces.AuthorizedGrant authorizedGrant, System.TimeSpan authorizationCodeExpiresIn);Parameters
authorizedGrant AuthorizedGrant
An object encapsulating the result of the authorization grant, including user authentication session and authorization context details.
authorizationCodeExpiresIn System.TimeSpan
Implements GenerateAuthorizationCodeAsync(AuthorizedGrant, TimeSpan)
Returns
System.Threading.Tasks.Task<System.String>
A task that resolves to the generated authorization code as a string.
AuthorizationCodeService.RemoveAuthorizationCodeAsync(string) Method
Atomically removes an authorization code from storage and returns the grant it held, in a
single get-and-remove operation. This is how a code is claimed for redemption: it enforces
the single-use guarantee against a race between two simultaneous redemptions of the same
code (RFC 6749 section 4.1.2) - every other caller finds the code already gone and receives an
invalid_grant failure.
One exception on a single node, and it is a loss rather than a duplication: a removal can end with NOBODY receiving the grant, when the claim expires mid-protocol. A store fault after the removal costs the grant the same way, and raises rather than answering.
Two callers both receiving it needs a SECOND NODE, and that holds of the storage this library
ships rather than of the seam: the read and the removal happen under one hold of a per-key gate,
so within one process a redeemer is never between them while another completes a take. A host
substituting its own IEntityStorage owns that property, and a naive get-then-remove
reopens the duplication on one node. Across processes the gate holds nothing either: the value is
read before the claim is taken, the second caller is handed what it read rather than what it
removed, and the reuse check sees no issued tokens. That is issue 435, and it needs a store
primitive Microsoft.Extensions.Caching.Distributed.IDistributedCache does not
expose.
public System.Threading.Tasks.Task<Abblix.Utils.Result<Abblix.Oidc.Server.Endpoints.Token.Interfaces.AuthorizedGrant,Abblix.Oidc.Server.Common.OidcError>> RemoveAuthorizationCodeAsync(string authorizationCode);Parameters
authorizationCode System.String
The authorization code to remove and claim.
Implements RemoveAuthorizationCodeAsync(string)
Returns
System.Threading.Tasks.Task<Abblix.Utils.Result<AuthorizedGrant,OidcError>>
The grant when this caller won the claim; an invalid_grantOidcError
otherwise. Otherwise is wider than the obvious list - a concurrent request, an earlier
consumption, an expiry, a code never issued - because the claim can also CONSUME the code and
still refuse, when the lock guarding it expires mid-protocol. So a refusal does not prove another
request took it, and looking for one is how that case is missed.
Remarks
A successfully claimed grant whose IssuedTokens is non-empty indicates the code was
already used to issue tokens (a sequential reuse), which the caller treats as a reuse to be
rejected and whose tokens are revoked.
AuthorizationCodeService.UpdateAuthorizationGrantAsync(string, AuthorizedGrant, TimeSpan) Method
Updates the authorization grant result based on a specific authorization code and client information. This method allows the authorization grant to be updated with new information or tokens as needed.
public System.Threading.Tasks.Task UpdateAuthorizationGrantAsync(string authorizationCode, Abblix.Oidc.Server.Endpoints.Token.Interfaces.AuthorizedGrant authorizedGrant, System.TimeSpan authorizationCodeExpiresIn);Parameters
authorizationCode System.String
The authorization code associated with the grant result to update.
authorizedGrant AuthorizedGrant
The updated authorization grant result containing the latest authentication and authorization details.
authorizationCodeExpiresIn System.TimeSpan
Implements UpdateAuthorizationGrantAsync(string, AuthorizedGrant, TimeSpan)
Returns
System.Threading.Tasks.Task
A task representing the asynchronous operation of updating the authorization grant result.