Перейти к содержимому
Эта страница ещё не переведена.

AuthorizationContextExtensions Class

Provides extension methods for working with AuthorizationContext objects, facilitating the conversion between authorization contexts and JWT claims.

C#
public static class AuthorizationContextExtensions

Inheritance System.Object → AuthorizationContextExtensions

Methods

AuthorizationContextExtensions.ApplyTo(this AuthorizationContext, JsonWebTokenPayload) Method

Applies the information from an AuthorizationContext to a JsonWebTokenPayload, converting the context into JWT claims.

C#
public static void ApplyTo(this Abblix.Oidc.Server.Common.AuthorizationContext context, Abblix.Jwt.JsonWebTokenPayload payload);

Parameters

context AuthorizationContext

The AuthorizationContext containing authorization details.

payload JsonWebTokenPayload

The JWT payload where the authorization context information will be applied as claims.

Remarks

This method is useful for embedding authorization details directly into a JWT, allowing for efficient transfer and validation of authorization information.

AuthorizationContextExtensions.ToAuthorizationContext(this JsonWebTokenPayload) Method

Creates an AuthorizationContext from a JsonWebTokenPayload, converting JWT claims back into an authorization context.

C#
public static Abblix.Oidc.Server.Common.AuthorizationContext ToAuthorizationContext(this Abblix.Jwt.JsonWebTokenPayload payload);

Parameters

payload JsonWebTokenPayload

The JWT payload containing claims that represent an authorization context.

Returns

AuthorizationContext
An instance of AuthorizationContext populated with information derived from the JWT claims.

Remarks

This method facilitates the extraction of authorization details from JWT claims, reconstructing an AuthorizationContext for further processing or validation.

AuthorizationContextExtensions.WithDefaultResource(this AuthorizationContext, Uri) Method

Names the given resource as the audience when the context names none, so a token says which party is meant to consume it rather than which one asked for it.

C#
public static Abblix.Oidc.Server.Common.AuthorizationContext WithDefaultResource(this Abblix.Oidc.Server.Common.AuthorizationContext context, System.Uri? defaultResource);

Parameters

context AuthorizationContext

The authorization context to complete.

defaultResource System.Uri

The resource to fall back on, or null to leave the context alone.

Returns

AuthorizationContext
The context, with the default resource applied where it was needed.

Remarks

RFC 9068 Section 3: "If the request does not include a `resource` parameter, the authorization server MUST use a default resource indicator in the `aud` claim." With no default supplied the context is returned untouched and the audience later falls back to the issuer (see ApplyTo(this AuthorizationContext, JsonWebTokenPayload)) - the behaviour changes only where a host states the default, because that value is read by every resource server in the deployment. A context that already names a resource or an audience is returned unchanged: it says who the token is for, and this only fills a gap.