Class CapabilityGrantValidationOptions
- Namespace
- AsiBackbone.Core.CapabilityGrants
- Assembly
- AsiBackbone.Core.dll
public sealed class CapabilityGrantValidationOptions
- Inheritance
-
CapabilityGrantValidationOptions
- Inherited Members
Properties
AcknowledgmentId
public string? AcknowledgmentId { get; }
Property Value
AllowedClockSkew
public TimeSpan AllowedClockSkew { get; }
Property Value
Audience
public string? Audience { get; }
Property Value
ExpectedOperationName
Gets the requested operation that the grant must identify, when operation binding is configured.
public string? ExpectedOperationName { get; }
Property Value
ExpectedProofKeyId
public string? ExpectedProofKeyId { get; }
Property Value
ExpectedProofKeyVersion
public string? ExpectedProofKeyVersion { get; }
Property Value
ExpectedProofPolicyHash
public string? ExpectedProofPolicyHash { get; }
Property Value
ExpectedProofPolicyVersion
public string? ExpectedProofPolicyVersion { get; }
Property Value
ExpectedSubjectId
Gets the authenticated subject that the grant must identify, when subject binding is configured.
public string? ExpectedSubjectId { get; }
Property Value
GatewayBinding
public string? GatewayBinding { get; }
Property Value
HandshakeId
public string? HandshakeId { get; }
Property Value
Issuer
public string? Issuer { get; }
Property Value
MaxUseCount
public int MaxUseCount { get; }
Property Value
PolicyHash
public string? PolicyHash { get; }
Property Value
PolicyVersion
public string? PolicyVersion { get; }
Property Value
ProofPayloadOptions
Gets the canonical payload options used to rebuild the grant payload when proof is required.
public CanonicalPayloadOptions? ProofPayloadOptions { get; }
Property Value
Remarks
Proof validation recomputes the canonical payload from the grant and compares its hash to the signed hash, so these options must match the options the issuer signed with. The default options bind every grant field except metadata, whose allow-list is empty until a host opts a key in.
RequireAcknowledgmentReference
public bool RequireAcknowledgmentReference { get; }
Property Value
RequireProof
public bool RequireProof { get; }
Property Value
RequireUseCheck
public bool RequireUseCheck { get; }
Property Value
RequiredProofHashAlgorithm
public string? RequiredProofHashAlgorithm { get; }
Property Value
RequiredProofProvider
public string? RequiredProofProvider { get; }
Property Value
ResourceBinding
public string? ResourceBinding { get; }
Property Value
Scopes
public IReadOnlyList<string> Scopes { get; }
Property Value
ValidationUtc
public DateTimeOffset? ValidationUtc { get; }
Property Value
Methods
Create(string?, string?, IEnumerable<string>?, DateTimeOffset?, string?, string?, string?, string?, string?, string?, bool, bool, bool, int, TimeSpan, string?, string?, string?, string?, string?, string?, CanonicalPayloadOptions?)
public static CapabilityGrantValidationOptions Create(string? issuer = null, string? audience = null, IEnumerable<string>? scopes = null, DateTimeOffset? validationUtc = null, string? policyVersion = null, string? policyHash = null, string? acknowledgmentId = null, string? handshakeId = null, string? gatewayBinding = null, string? resourceBinding = null, bool requireProof = false, bool requireAcknowledgmentReference = false, bool requireUseCheck = false, int maxUseCount = 1, TimeSpan allowedClockSkew = default, string? expectedProofKeyId = null, string? expectedProofKeyVersion = null, string? expectedProofPolicyVersion = null, string? expectedProofPolicyHash = null, string? requiredProofProvider = null, string? requiredProofHashAlgorithm = null, CanonicalPayloadOptions? proofPayloadOptions = null)
Parameters
issuerstringaudiencestringscopesIEnumerable<string>validationUtcDateTimeOffset?policyVersionstringpolicyHashstringacknowledgmentIdstringhandshakeIdstringgatewayBindingstringresourceBindingstringrequireProofboolrequireAcknowledgmentReferenceboolrequireUseCheckboolmaxUseCountintallowedClockSkewTimeSpanexpectedProofKeyIdstringexpectedProofKeyVersionstringexpectedProofPolicyVersionstringexpectedProofPolicyHashstringrequiredProofProviderstringrequiredProofHashAlgorithmstringproofPayloadOptionsCanonicalPayloadOptions
Returns
CreateBoundExecutionBoundary(CapabilityGrantBindingExpectations, string?, string?, IEnumerable<string>?, DateTimeOffset?, string?, string?, string?, string?, string?, string?, bool, bool, int, TimeSpan, string?, string?, string?, string?, string?, string?, CanonicalPayloadOptions?)
Creates a proof-verifying execution-boundary profile with authoritative host binding expectations.
public static CapabilityGrantValidationOptions CreateBoundExecutionBoundary(CapabilityGrantBindingExpectations bindingExpectations, string? issuer = null, string? audience = null, IEnumerable<string>? scopes = null, DateTimeOffset? validationUtc = null, string? policyVersion = null, string? policyHash = null, string? acknowledgmentId = null, string? handshakeId = null, string? gatewayBinding = null, string? resourceBinding = null, bool requireAcknowledgmentReference = false, bool requireUseCheck = true, int maxUseCount = 1, TimeSpan allowedClockSkew = default, string? expectedProofKeyId = null, string? expectedProofKeyVersion = null, string? expectedProofPolicyVersion = null, string? expectedProofPolicyHash = null, string? requiredProofProvider = null, string? requiredProofHashAlgorithm = null, CanonicalPayloadOptions? proofPayloadOptions = null)
Parameters
bindingExpectationsCapabilityGrantBindingExpectationsissuerstringaudiencestringscopesIEnumerable<string>validationUtcDateTimeOffset?policyVersionstringpolicyHashstringacknowledgmentIdstringhandshakeIdstringgatewayBindingstringresourceBindingstringrequireAcknowledgmentReferenceboolrequireUseCheckboolmaxUseCountintallowedClockSkewTimeSpanexpectedProofKeyIdstringexpectedProofKeyVersionstringexpectedProofPolicyVersionstringexpectedProofPolicyHashstringrequiredProofProviderstringrequiredProofHashAlgorithmstringproofPayloadOptionsCanonicalPayloadOptions
Returns
CreateExecutionBoundary(string?, string?, IEnumerable<string>?, DateTimeOffset?, string?, string?, string?, string?, string?, string?, bool, bool, int, TimeSpan, string?, string?, string?, string?, string?, string?, CanonicalPayloadOptions?)
Obsolete. Retains the legacy execution-boundary signature for binary compatibility and always fails closed.
[Obsolete("CreateExecutionBoundary always fails closed and is retained only for binary compatibility. Use CreateBoundExecutionBoundary(CapabilityGrantBindingExpectations, ...) instead. Planned removal in 8.0.", DiagnosticId = "ASIB901", UrlFormat = "https://asibackbone.github.io/AsiBackbone/articles/capability-grant-hardening.html#legacy-createexecutionboundary-deprecation")]
public static CapabilityGrantValidationOptions CreateExecutionBoundary(string? issuer = null, string? audience = null, IEnumerable<string>? scopes = null, DateTimeOffset? validationUtc = null, string? policyVersion = null, string? policyHash = null, string? acknowledgmentId = null, string? handshakeId = null, string? gatewayBinding = null, string? resourceBinding = null, bool requireAcknowledgmentReference = false, bool requireUseCheck = true, int maxUseCount = 1, TimeSpan allowedClockSkew = default, string? expectedProofKeyId = null, string? expectedProofKeyVersion = null, string? expectedProofPolicyVersion = null, string? expectedProofPolicyHash = null, string? requiredProofProvider = null, string? requiredProofHashAlgorithm = null, CanonicalPayloadOptions? proofPayloadOptions = null)
Parameters
issuerstringaudiencestringscopesIEnumerable<string>validationUtcDateTimeOffset?policyVersionstringpolicyHashstringacknowledgmentIdstringhandshakeIdstringgatewayBindingstringresourceBindingstringrequireAcknowledgmentReferenceboolrequireUseCheckboolmaxUseCountintallowedClockSkewTimeSpanexpectedProofKeyIdstringexpectedProofKeyVersionstringexpectedProofPolicyVersionstringexpectedProofPolicyHashstringrequiredProofProviderstringrequiredProofHashAlgorithmstringproofPayloadOptionsCanonicalPayloadOptions
Returns
Remarks
This method is retained only for compatibility and always throws InvalidOperationException.
Replace calls with CreateBoundExecutionBoundary(CapabilityGrantBindingExpectations, ...), whose required
first argument supplies the authoritative subject and optional operation binding. The warning remains non-error
in the 7.x line; removal is planned for the next permitted major version.
CreateMetadataValidation(string?, string?, IEnumerable<string>?, DateTimeOffset?, string?, string?, string?, string?, string?, string?, bool, TimeSpan)
public static CapabilityGrantValidationOptions CreateMetadataValidation(string? issuer = null, string? audience = null, IEnumerable<string>? scopes = null, DateTimeOffset? validationUtc = null, string? policyVersion = null, string? policyHash = null, string? acknowledgmentId = null, string? handshakeId = null, string? gatewayBinding = null, string? resourceBinding = null, bool requireAcknowledgmentReference = false, TimeSpan allowedClockSkew = default)
Parameters
issuerstringaudiencestringscopesIEnumerable<string>validationUtcDateTimeOffset?policyVersionstringpolicyHashstringacknowledgmentIdstringhandshakeIdstringgatewayBindingstringresourceBindingstringrequireAcknowledgmentReferenceboolallowedClockSkewTimeSpan
Returns
WithExpectedBindings(string?, string?)
Creates a copy with optional host expectations for the authenticated subject and requested operation.
public CapabilityGrantValidationOptions WithExpectedBindings(string? expectedSubjectId = null, string? expectedOperationName = null)