Перейти к содержимому
Эта страница ещё не переведена.

IAuthorizationRequestStorage Interface

Provides mechanisms for securely storing and retrieving OAuth 2.0 authorization requests. This interface abstracts the storage layer, allowing for implementation-specific details such as database, cache or filesystem storage.

C#
public interface IAuthorizationRequestStorage

Derived
↳ AuthorizationRequestStorage

Methods

IAuthorizationRequestStorage.StoreAsync(AuthorizationRequest, TimeSpan) Method

Asynchronously stores the provided authorization request in a secure manner and returns a unique identifier for it. This identifier can be used to retrieve the request at a later time, facilitating mechanisms like the Pushed Authorization Request (PAR). This method also accepts an expiration time for the request, allowing the storage mechanism to automatically invalidate the request after a certain period.

C#
System.Threading.Tasks.Task<Abblix.Oidc.Server.Endpoints.PushedAuthorization.Interfaces.PushedAuthorizationResponse> StoreAsync(Abblix.Oidc.Server.Model.AuthorizationRequest request, System.TimeSpan expiresIn);

Parameters

request AuthorizationRequest

The AuthorizationRequest instance to be stored.

expiresIn System.TimeSpan

The duration after which the stored request should expire and be considered invalid.

Returns

System.Threading.Tasks.Task<PushedAuthorizationResponse>
A System.Threading.Tasks.Task that, when completed successfully, yields a PushedAuthorizationResponse containing the unique identifier of the stored request and its expiration information.

IAuthorizationRequestStorage.TryGetAsync(Uri, bool) Method

Asynchronously retrieves an authorization request using a previously stored unique identifier. This method facilitates the retrieval of authorization requests for further processing or validation. The shouldRemove parameter controls whether the request is deleted from storage upon retrieval, which is what narrows the window in which it is retrieved twice. RFC 9126 puts the MUST on the client - "the client MUST only use a request_uri value once" (Section 4, Authorization Request) - and asks the authorization server for no more than a SHOULD, twice: Section 4 hedges it with a MAY for a user reloading their user agent, and Section 7.3 states it plainly, "the authorization server SHOULD make the request URIs one-time use". Consuming it here is therefore this library's choice, taken on the specification's recommendation rather than on its requirement. Narrows rather than closes: the returns block says what a null covers.

C#
System.Threading.Tasks.Task<Abblix.Oidc.Server.Model.AuthorizationRequest?> TryGetAsync(System.Uri requestUri, bool shouldRemove=false);

Parameters

requestUri System.Uri

The unique identifier of the authorization request, typically a URI, used to locate the request in storage.

shouldRemove System.Boolean

Specifies whether the request should be removed from storage on retrieval, for the one-time use scenarios where a second retrieval must not succeed.

Returns

System.Threading.Tasks.Task<AuthorizationRequest>
A System.Threading.Tasks.Task that, when completed successfully, yields the AuthorizationRequest associated with the specified identifier, or null. With shouldRemove set, null is wider than "no such request": it also covers the entry having expired, another caller having removed it, and a claim that expired mid-protocol on a single caller with nobody to lose to. A store call that fails after the removal raises instead of answering.