Skip to main content

AuthorizationClient

Namespace: Meshmakers.Octo.Sdk.ServiceClient.Authorization

Implements IAuthorizationClient using Duende.IdentityModel.

public class AuthorizationClient : IAuthorizationClient

Inheritance Object → AuthorizationClient
Implements IAuthorizationClient

Constructors​

AuthorizationClient(IOptionsMonitor<AuthorizationOptions>)​

Initializes a new instance of the AuthorizationClient class.

public AuthorizationClient(IOptionsMonitor<AuthorizationOptions> options)

Parameters​

options IOptionsMonitor<AuthorizationOptions>

Methods​

GetUserInfoAsync(String)​

public Task<UserInfoData> GetUserInfoAsync(string accessToken)

Parameters​

accessToken String

Returns​

Task<UserInfoData>

IntrospectApiResource(String, String, String)​

public Task<bool> IntrospectApiResource(string accessToken, string apiName, string apiSecret)

Parameters​

accessToken String

apiName String

apiSecret String

Returns​

Task<Boolean>

Rebase(String)​

Rewrites an endpoint the discovery document advertises under one of AuthorizationOptions.AdditionalValidIssuers onto the authority this client was actually configured with (AB#5081). Returns the value unchanged when no allow-list is configured, when the endpoint already sits on the authority, or when it sits somewhere else entirely.

protected string Rebase(string endpoint)

Parameters​

endpoint String
Endpoint URL from the discovery document.

Returns​

String
The endpoint, rebased onto the configured authority where applicable.

Remarks:

🔴 Accepting a foreign endpoint host is not enough — it has to be reachable. In the split-horizon case the document names an address the client cannot dial: a container reaches the host's identity service as https://mac.local:5003, while the document advertises every endpoint under https://localhost:5003, which inside that container is the container itself. Merely widening the validation would turn "issuer name does not match authority" into "connection refused".

Rebasing is also stricter than IdentityModel's default, not looser: afterwards this client only ever talks to the host it was configured to talk to. The default follows whatever host the document names, so a substituted document can redirect the token request; here it cannot.

Every disco.*Endpoint read goes through this method. A new call site that forgets it keeps working everywhere except split-horizon, where it fails at connect time — so add the wrapper when you add the site.

GetDiscoveryResponse()​

Gets the discovery response.

protected Task<DiscoveryDocumentResponse> GetDiscoveryResponse()

Returns​

Task<DiscoveryDocumentResponse>