Перейти к содержимому
Эта страница ещё не переведена.

DeviceAuthorizationRequest Class

Represents a stored device authorization request as defined in RFC 8628. This record is used to persist the state of a device authorization flow between the initial request and when the user completes authentication.

C#
public record DeviceAuthorizationRequest : System.IEquatable<Abblix.Oidc.Server.Features.DeviceAuthorization.DeviceAuthorizationRequest>

Inheritance System.Object → DeviceAuthorizationRequest

Implements System.IEquatable<DeviceAuthorizationRequest>

Constructors

DeviceAuthorizationRequest(string, string[], Uri[], string) Constructor

Represents a stored device authorization request as defined in RFC 8628. This record is used to persist the state of a device authorization flow between the initial request and when the user completes authentication.

C#
public DeviceAuthorizationRequest(string ClientId, string[] Scope, System.Uri[]? Resources, string UserCode);

Parameters

ClientId System.String

The client identifier that initiated the device authorization request.

Scope System.String[]

The requested scopes for the authorization.

Resources System.Uri[]

The requested resources (RFC 8707) for the authorization.

UserCode System.String

The user-friendly code displayed to the user for verification.

Properties

DeviceAuthorizationRequest.AuthorizationDetails Property

RFC 9396 Section 3 Rich Authorization Requests array carried from the original /device_authorization request. The host's user-verification step reads this (via ValidUserCode) to render structured consent, then threads it into the AuthorizedGrant's AuthorizationContext when approving; the eventual access token issued via the device-code grant emits the claim byte-exact.

C#
public System.Text.Json.Nodes.JsonArray? AuthorizationDetails { get; set; }

Property Value

System.Text.Json.Nodes.JsonArray

DeviceAuthorizationRequest.AuthorizedGrant Property

The authorized grant containing the user's authentication session and authorization context. This is set when the user successfully authorizes the device.

C#
public Abblix.Oidc.Server.Endpoints.Token.Interfaces.AuthorizedGrant? AuthorizedGrant { get; set; }

Property Value

AuthorizedGrant

DeviceAuthorizationRequest.ClientId Property

The client identifier that initiated the device authorization request.

C#
public string ClientId { get; init; }

Property Value

System.String

DeviceAuthorizationRequest.ExpiresAt Property

The absolute time when this device authorization request expires (RFC 8628 Section 3.2 fixed lifetime). Seeded by the storage on StoreAsync and used to cap the refreshed cache TTL at the remaining lifetime, so regular polling cannot extend the code.

C#
public System.DateTimeOffset ExpiresAt { get; set; }

Property Value

System.DateTimeOffset

DeviceAuthorizationRequest.NextPollAt Property

Specifies the next time the client should poll for updates regarding the authorization request. This helps manage the timing of polling requests and enforces rate limiting.

C#
public System.Nullable<System.DateTimeOffset> NextPollAt { get; set; }

Property Value

System.Nullable<System.DateTimeOffset>

DeviceAuthorizationRequest.Resources Property

The requested resources (RFC 8707) for the authorization.

C#
public System.Uri[]? Resources { get; init; }

Property Value

System.Uri[]

DeviceAuthorizationRequest.Scope Property

The requested scopes for the authorization.

C#
public string[] Scope { get; init; }

Property Value

System.String[]

DeviceAuthorizationRequest.Status Property

Indicates the current status of the device authorization request. Defaults to Pending, reflecting that the user has not yet completed authentication.

C#
public Abblix.Oidc.Server.Features.DeviceAuthorization.DeviceAuthorizationStatus Status { get; set; }

Property Value

DeviceAuthorizationStatus

DeviceAuthorizationRequest.UserCode Property

The user-friendly code displayed to the user for verification.

C#
public string UserCode { get; init; }

Property Value

System.String

Methods

DeviceAuthorizationRequest.HasLifetimeLeft(DateTimeOffset, TimeSpan) Method

Whether the fixed lifetime still has time left at now, handing back how much.

C#
public bool HasLifetimeLeft(System.DateTimeOffset now, out System.TimeSpan remaining);

Parameters

now System.DateTimeOffset

The instant to judge against, from the caller's own time provider.

remaining System.TimeSpan

How much lifetime is left; zero or negative when there is none.

Returns

System.Boolean
true while the request can still be acted on.

Remarks

The comparison sits here because it was being written out at each caller, and one of them forgot it: user code verification, the step the end user reaches first, decided on Status alone and answered a full result for a record the approval would then refuse.

It is now the only verdict on that boundary: DeviceCodeGrantHandler asks this rather than comparing for itself, so the token endpoint and the three paths above cannot disagree about a code polled at exactly its expiry. What holds it is that relaxing this one predicate turns rows red on both sides of that seam - the two approval rows and the token endpoint's - rather than two comparisons happening to stay in step.

It hands back the remaining time because the callers that act on the record need it: a decision is written with that as the cache TTL, so the code cannot be extended by being decided on.