Перейти к содержимому
Эта страница ещё не переведена.

IAuthenticationCompletionHandler Interface

Handles CIBA authentication completion by routing to the appropriate delivery mode handler (poll, ping, or push) based on the client's configured backchannel_token_delivery_mode.

C#
public interface IAuthenticationCompletionHandler

Derived
↳ AuthenticationCompletionRouter

Properties

IAuthenticationCompletionHandler.TokenDeliveryModesSupported Property

Token delivery modes (poll, ping, push) for which a handler is registered with the DI container. Used to populate the discovery document's backchannel_token_delivery_modes_supported field so it reflects only modes the host actually supports.

C#
System.Collections.Generic.IEnumerable<string> TokenDeliveryModesSupported { get; }

Property Value

System.Collections.Generic.IEnumerable<System.String>

Methods

IAuthenticationCompletionHandler.CompleteAsync(string, BackChannelAuthenticationRequest, TimeSpan) Method

Completes the authentication process and handles token delivery according to the client's configured delivery mode.

C#
System.Threading.Tasks.Task CompleteAsync(string authenticationRequestId, Abblix.Oidc.Server.Features.BackChannelAuthentication.BackChannelAuthenticationRequest request, System.TimeSpan expiresIn);

Parameters

authenticationRequestId System.String

The auth_req_id identifying the authentication request.

request BackChannelAuthenticationRequest

The authentication request carrying the grant the end user approved. Its own Status is not read: whether this request may still be answered is decided from the STORED record, so a caller cannot make the decision by setting a field on its own copy.

expiresIn System.TimeSpan

How long the authenticated request remains valid for token retrieval.

Returns

System.Threading.Tasks.Task
A task representing the asynchronous completion operation.

Exceptions

System.InvalidOperationException
The store does not hold a PENDING record under this identifier. Stated as what must be true rather than as a list of causes, because the causes are more numerous than they look and this seam cannot tell them apart: the request may have been answered, refused or expired, its record may have been redeemed and removed by a poll, removed by push's own refusal path after a configuration fault where nothing was answered at all, evicted, or never stored. A host that persists the status itself before calling lands here too, on its FIRST completion and with nothing over-granted.

Completing a request that is not pending would deliver a second answer for one authentication. Recovering from a failed delivery therefore means asking the end user again, not repeating the call.

Remarks

This method automatically:

  • Retrieves client information to determine the delivery mode
  • Selects the appropriate handler (PollModeCompletionHandler, PingModeCompletionHandler, or PushModeCompletionHandler)
  • Delegates to the mode-specific implementation for token delivery