ProofError Class
Describes why a DPoP proof was rejected. Reason is a stable token suitable for log filters and metric labels; Detail is a human-readable hint.
public sealed record ProofError : System.IEquatable<Abblix.Oidc.Server.Features.DPoP.ProofError>Inheritance System.Object → ProofError
Implements System.IEquatable<ProofError>
Remarks
Detail CAN carry what the client put in the token: the JWT core writes several of its
descriptions by quoting the value it refused - an unhandled crit name, an unregistered
algorithm - and this type passes those through unchanged. An earlier version of this summary said
the value must not contain such input, which made it read as safe to surface; it was already
carrying it.
So the library puts it nowhere: no response, no log, no metric label. What a host reads off the ProofError its own call returned is its own to sanitise, and a host that copies it into a response is echoing the client's bytes.
Constructors
ProofError(string, string) Constructor
Describes why a DPoP proof was rejected. Reason is a stable token suitable for log filters and metric labels; Detail is a human-readable hint.
public ProofError(string Reason, string? Detail=null);Parameters
Reason System.String
A stable, machine-friendly token (e.g. invalid_typ,
signature_invalid, htm_mismatch).
Detail System.String
Optional human-readable diagnostic.
Remarks
Detail CAN carry what the client put in the token: the JWT core writes several of its
descriptions by quoting the value it refused - an unhandled crit name, an unregistered
algorithm - and this type passes those through unchanged. An earlier version of this summary said
the value must not contain such input, which made it read as safe to surface; it was already
carrying it.
So the library puts it nowhere: no response, no log, no metric label. What a host reads off the ProofError its own call returned is its own to sanitise, and a host that copies it into a response is echoing the client's bytes.
Properties
ProofError.Detail Property
Optional human-readable diagnostic.
public string? Detail { get; init; }Property Value
ProofError.Reason Property
A stable, machine-friendly token (e.g. invalid_typ,
signature_invalid, htm_mismatch).
public string Reason { get; init; }