SubjectTypeValidator Class
Validates the OIDC Core Section 8 subject_type metadata and computes the pairwise sector
identifier. When pairwise is requested, a supplied sector_identifier_uri (HTTPS) is
dereferenced and every URI the registration is required to have listed there is checked against
its contents; otherwise the host is taken from the registered redirect URIs, which must agree on
one (OIDC Core Section 8.1). A backchannel client that registered NO redirect URI takes its host
instead from the URI CIBA Core 1.0 Section 4 puts in their place - the jwks_uri in poll and
ping, the backchannel_client_notification_endpoint in push. Registering both is allowed and
they need not agree: the redirect URIs decide, and the backchannel URI is only ever the sector of a
client that has none.
The resolved host is stored on the context for later persistence.
public class SubjectTypeValidator : Abblix.Oidc.Server.Endpoints.DynamicClientManagement.Validation.IClientRegistrationContextValidatorInheritance System.Object → SubjectTypeValidator
Implements IClientRegistrationContextValidator
Constructors
SubjectTypeValidator(ILogger<SubjectTypeValidator>, ISecureHttpFetcher) Constructor
Validates the OIDC Core Section 8 subject_type metadata and computes the pairwise sector
identifier. When pairwise is requested, a supplied sector_identifier_uri (HTTPS) is
dereferenced and every URI the registration is required to have listed there is checked against
its contents; otherwise the host is taken from the registered redirect URIs, which must agree on
one (OIDC Core Section 8.1). A backchannel client that registered NO redirect URI takes its host
instead from the URI CIBA Core 1.0 Section 4 puts in their place - the jwks_uri in poll and
ping, the backchannel_client_notification_endpoint in push. Registering both is allowed and
they need not agree: the redirect URIs decide, and the backchannel URI is only ever the sector of a
client that has none.
The resolved host is stored on the context for later persistence.
public SubjectTypeValidator(Microsoft.Extensions.Logging.ILogger<Abblix.Oidc.Server.Endpoints.DynamicClientManagement.Validation.SubjectTypeValidator> logger, Abblix.Oidc.Server.Features.SecureHttpFetch.ISecureHttpFetcher secureHttpFetcher);Parameters
logger Microsoft.Extensions.Logging.ILogger<SubjectTypeValidator>
Logger used for warnings about sector-identifier mismatches.
secureHttpFetcher ISecureHttpFetcher
SSRF-protected fetcher for the sector identifier document.
Methods
SubjectTypeValidator.ValidateAsync(ClientRegistrationValidationContext) Method
Validates the slice of registration metadata this implementation owns. May mutate ClientRegistrationValidationContext with derived values (for example the resolved sector identifier).
public System.Threading.Tasks.Task<Abblix.Oidc.Server.Common.OidcError?> ValidateAsync(Abblix.Oidc.Server.Endpoints.DynamicClientManagement.Validation.ClientRegistrationValidationContext context);Parameters
context ClientRegistrationValidationContext
The shared validation context for the current request.
Implements ValidateAsync(ClientRegistrationValidationContext)
Returns
System.Threading.Tasks.Task<OidcError>
An OidcError describing the rejection, or null when valid.