AuthenticatorOptions
Namespace: Meshmakers.Octo.Sdk.ServiceClient.Authentication
Options for the authenticator.
public class AuthenticatorOptions : AuthorizationOptions
Inheritance Object → AuthorizationOptions → AuthenticatorOptions
Properties
IssuerUri
Issuer URI of the authorization server.
public string IssuerUri { get; set; }
Property Value
ClientId
Client ID of the authorization client.
public string ClientId { get; set; }
Property Value
ClientSecret
Client secret of the authorization client.
public string ClientSecret { get; set; }
Property Value
TenantId
Tenant ID to include as acr_values in authorization requests.
public string TenantId { get; set; }
Property Value
AdditionalValidIssuers
Issuer values that are accepted in the discovery document in addition to
AuthorizationOptions.IssuerUri (AB#5081). Empty by default, which keeps the strict
IdentityModel behaviour: the document's issuer must equal the authority the client
was pointed at.
public String[] AdditionalValidIssuers { get; set; }
Property Value
Remarks:
This exists for split-horizon deployments, where the address a client reaches
the identity service on is not the address the service knows itself by. The case that
produced it: an adapter running in a container reaches the host's identity service as
https://mac.local:5003, while that service issues and advertises
https://localhost:5003/. Discovery then fails with "Issuer name does not match
authority" and no token is ever obtained.
The inbound direction has had this for a while — Adapter:AdditionalValidIssuers
decides which issuers a secured route accepts in a presented token. This is its
outbound counterpart, and it is deliberately shaped the same way: an explicit
allow-list, never a switch that turns the check off. A blanket
ValidateIssuerName = false would accept any issuer from whatever host
answered the discovery request, which is precisely the substitution the check exists
to prevent.
Constructors
AuthenticatorOptions()
public AuthenticatorOptions()