Перейти к содержимому
Эта страница ещё не переведена.

AuthorizationCodeReusePreventingDecorator Class

Refuses a second redemption of an authorization code, and revokes the tokens the first one issued, in compliance with OAuth 2.0 security best practices. Two defences, split by WHEN the repeat arrives rather than by where: the claim refuses one arriving beside the first, and the issued tokens written back at the key catch one arriving after it. Both hold across processes.

C#
public class AuthorizationCodeReusePreventingDecorator : Abblix.Oidc.Server.Endpoints.Token.Interfaces.ITokenRequestProcessor

Inheritance System.Object → AuthorizationCodeReusePreventingDecorator

Implements ITokenRequestProcessor

Remarks

Neither is complete on its own terms. The claim reads the value under the same hold of the gate that removes it, so on ONE node two callers cannot be handed the same grant; across processes the gate holds nothing and both can be, which is issue 435. And the write-back is what the second defence rests on, so a first redemption that ends without issuing tokens leaves nothing for it to catch. The refusal this class returns is the same string either way.

This class decorates the standard token request processing flow with additional security measures to ensure the integrity of the authorization process. It detects when an authorization code, which should only be used once, is attempted to be used multiple times. In such cases, it revokes any tokens previously issued with that code and denies the request, effectively mitigating potential security risks associated with code reuse.

Constructors

AuthorizationCodeReusePreventingDecorator(ITokenRequestProcessor, ITokenRegistry, IAuthorizationCodeService) Constructor

Refuses a second redemption of an authorization code, and revokes the tokens the first one issued, in compliance with OAuth 2.0 security best practices. Two defences, split by WHEN the repeat arrives rather than by where: the claim refuses one arriving beside the first, and the issued tokens written back at the key catch one arriving after it. Both hold across processes.

C#
public AuthorizationCodeReusePreventingDecorator(Abblix.Oidc.Server.Endpoints.Token.Interfaces.ITokenRequestProcessor processor, Abblix.Oidc.Server.Features.Storages.ITokenRegistry tokenRegistry, Abblix.Oidc.Server.Features.Storages.IAuthorizationCodeService authorizationCodeService);

Parameters

processor ITokenRequestProcessor

The underlying token request processor to be enhanced.

tokenRegistry ITokenRegistry

The registry used for managing token states and revocation.

authorizationCodeService IAuthorizationCodeService

The service responsible for managing the lifecycle of authorization codes.

Remarks

Neither is complete on its own terms. The claim reads the value under the same hold of the gate that removes it, so on ONE node two callers cannot be handed the same grant; across processes the gate holds nothing and both can be, which is issue 435. And the write-back is what the second defence rests on, so a first redemption that ends without issuing tokens leaves nothing for it to catch. The refusal this class returns is the same string either way.

This class decorates the standard token request processing flow with additional security measures to ensure the integrity of the authorization process. It detects when an authorization code, which should only be used once, is attempted to be used multiple times. In such cases, it revokes any tokens previously issued with that code and denies the request, effectively mitigating potential security risks associated with code reuse.

Methods

AuthorizationCodeReusePreventingDecorator.ProcessAsync(ValidTokenRequest) Method

Processes a valid token request, including revoking existing tokens if necessary and registering new tokens.

C#
public System.Threading.Tasks.Task<Abblix.Utils.Result<Abblix.Oidc.Server.Endpoints.Token.Interfaces.TokenIssued,Abblix.Oidc.Server.Common.OidcError>> ProcessAsync(Abblix.Oidc.Server.Endpoints.Token.Interfaces.ValidTokenRequest request);

Parameters

request ValidTokenRequest

The valid token request to process.

Implements ProcessAsync(ValidTokenRequest)

Returns

System.Threading.Tasks.Task<Abblix.Utils.Result<TokenIssued,OidcError>>
A task that returns a TokenIssued on success or an OidcError on failure.