Перейти к содержимому
Эта страница ещё не переведена.

Abblix.Oidc.Server.Features.ReplayPrevention Namespace

Classes
DistributedJwtReplayCacheThe deprecated contract's default implementation, kept so a host that resolves IJwtReplayCache still receives a working object. It stores nothing of its own: every reservation goes to the same IReplayCache the server's own consumers use, so the deprecated and current spellings share one set of entries and cannot disagree about whether an identifier has been seen.
ServiceCollectionExtensionsWires replay protection, which several unrelated features need and none of them owns: JWT-bearer assertions (RFC 7523 Section 3), client assertions, and DPoP proofs (RFC 9449 Section 11.1) all reserve identifiers in the same place.
Interfaces
IJwtReplayCacheTracks JWT IDs (jti claims) presented to the server, so a JWT-bearing flow can detect replay attempts. Both RFC 7523 §3 (JWT-bearer-grant assertion replay) and RFC 9449 §11.1 (DPoP proof replay) want this primitive; it is intentionally namespace-neutral so a single distributed-cache instance serves every consumer.