AuthorizationClient
Namespace: Meshmakers.Octo.Sdk.ServiceClient.Authorization
Implements IAuthorizationClient using Duende.IdentityModel.
public class AuthorizationClient : IAuthorizationClient
Inheritance Object → AuthorizationClient
Implements IAuthorizationClient
Constructors
AuthorizationClient(IOptionsMonitor<AuthorizationOptions>)
Initializes a new instance of the AuthorizationClient class.
public AuthorizationClient(IOptionsMonitor<AuthorizationOptions> options)
Parameters
options IOptionsMonitor<AuthorizationOptions>
Methods
GetUserInfoAsync(String)
public Task<UserInfoData> GetUserInfoAsync(string accessToken)
Parameters
accessToken String
Returns
IntrospectApiResource(String, String, String)
public Task<bool> IntrospectApiResource(string accessToken, string apiName, string apiSecret)
Parameters
accessToken String
apiName String
apiSecret String
Returns
Rebase(String)
Rewrites an endpoint the discovery document advertises under one of AuthorizationOptions.AdditionalValidIssuers onto the authority this client was actually configured with (AB#5081). Returns the value unchanged when no allow-list is configured, when the endpoint already sits on the authority, or when it sits somewhere else entirely.
protected string Rebase(string endpoint)
Parameters
endpoint String
Endpoint URL from the discovery document.
Returns
String
The endpoint, rebased onto the configured authority where applicable.
Remarks:
🔴 Accepting a foreign endpoint host is not enough — it has to be reachable. In the
split-horizon case the document names an address the client cannot dial: a container
reaches the host's identity service as https://mac.local:5003, while the document
advertises every endpoint under https://localhost:5003, which inside that container
is the container itself. Merely widening the validation would turn "issuer name does not
match authority" into "connection refused".
Rebasing is also stricter than IdentityModel's default, not looser: afterwards this client only ever talks to the host it was configured to talk to. The default follows whatever host the document names, so a substituted document can redirect the token request; here it cannot.
Every disco.*Endpoint read goes through this method. A new call site that
forgets it keeps working everywhere except split-horizon, where it fails at connect
time — so add the wrapper when you add the site.
GetDiscoveryResponse()
Gets the discovery response.
protected Task<DiscoveryDocumentResponse> GetDiscoveryResponse()