Table of Contents

Class CapabilityGrantValidationOptions

Namespace
AsiBackbone.Core.CapabilityGrants
Assembly
AsiBackbone.Core.dll
public sealed class CapabilityGrantValidationOptions
Inheritance
CapabilityGrantValidationOptions
Inherited Members

Properties

AcknowledgmentId

public string? AcknowledgmentId { get; }

Property Value

string

AllowedClockSkew

public TimeSpan AllowedClockSkew { get; }

Property Value

TimeSpan

Audience

public string? Audience { get; }

Property Value

string

ExpectedOperationName

Gets the requested operation that the grant must identify, when operation binding is configured.

public string? ExpectedOperationName { get; }

Property Value

string

ExpectedProofKeyId

public string? ExpectedProofKeyId { get; }

Property Value

string

ExpectedProofKeyVersion

public string? ExpectedProofKeyVersion { get; }

Property Value

string

ExpectedProofPolicyHash

public string? ExpectedProofPolicyHash { get; }

Property Value

string

ExpectedProofPolicyVersion

public string? ExpectedProofPolicyVersion { get; }

Property Value

string

ExpectedSubjectId

Gets the authenticated subject that the grant must identify, when subject binding is configured.

public string? ExpectedSubjectId { get; }

Property Value

string

GatewayBinding

public string? GatewayBinding { get; }

Property Value

string

HandshakeId

public string? HandshakeId { get; }

Property Value

string

Issuer

public string? Issuer { get; }

Property Value

string

MaxUseCount

public int MaxUseCount { get; }

Property Value

int

PolicyHash

public string? PolicyHash { get; }

Property Value

string

PolicyVersion

public string? PolicyVersion { get; }

Property Value

string

ProofPayloadOptions

Gets the canonical payload options used to rebuild the grant payload when proof is required.

public CanonicalPayloadOptions? ProofPayloadOptions { get; }

Property Value

CanonicalPayloadOptions

Remarks

Proof validation recomputes the canonical payload from the grant and compares its hash to the signed hash, so these options must match the options the issuer signed with. The default options bind every grant field except metadata, whose allow-list is empty until a host opts a key in.

RequireAcknowledgmentReference

public bool RequireAcknowledgmentReference { get; }

Property Value

bool

RequireProof

public bool RequireProof { get; }

Property Value

bool

RequireUseCheck

public bool RequireUseCheck { get; }

Property Value

bool

RequiredProofHashAlgorithm

public string? RequiredProofHashAlgorithm { get; }

Property Value

string

RequiredProofProvider

public string? RequiredProofProvider { get; }

Property Value

string

ResourceBinding

public string? ResourceBinding { get; }

Property Value

string

Scopes

public IReadOnlyList<string> Scopes { get; }

Property Value

IReadOnlyList<string>

ValidationUtc

public DateTimeOffset? ValidationUtc { get; }

Property Value

DateTimeOffset?

Methods

Create(string?, string?, IEnumerable<string>?, DateTimeOffset?, string?, string?, string?, string?, string?, string?, bool, bool, bool, int, TimeSpan, string?, string?, string?, string?, string?, string?, CanonicalPayloadOptions?)

public static CapabilityGrantValidationOptions Create(string? issuer = null, string? audience = null, IEnumerable<string>? scopes = null, DateTimeOffset? validationUtc = null, string? policyVersion = null, string? policyHash = null, string? acknowledgmentId = null, string? handshakeId = null, string? gatewayBinding = null, string? resourceBinding = null, bool requireProof = false, bool requireAcknowledgmentReference = false, bool requireUseCheck = false, int maxUseCount = 1, TimeSpan allowedClockSkew = default, string? expectedProofKeyId = null, string? expectedProofKeyVersion = null, string? expectedProofPolicyVersion = null, string? expectedProofPolicyHash = null, string? requiredProofProvider = null, string? requiredProofHashAlgorithm = null, CanonicalPayloadOptions? proofPayloadOptions = null)

Parameters

issuer string
audience string
scopes IEnumerable<string>
validationUtc DateTimeOffset?
policyVersion string
policyHash string
acknowledgmentId string
handshakeId string
gatewayBinding string
resourceBinding string
requireProof bool
requireAcknowledgmentReference bool
requireUseCheck bool
maxUseCount int
allowedClockSkew TimeSpan
expectedProofKeyId string
expectedProofKeyVersion string
expectedProofPolicyVersion string
expectedProofPolicyHash string
requiredProofProvider string
requiredProofHashAlgorithm string
proofPayloadOptions CanonicalPayloadOptions

Returns

CapabilityGrantValidationOptions

CreateBoundExecutionBoundary(CapabilityGrantBindingExpectations, string?, string?, IEnumerable<string>?, DateTimeOffset?, string?, string?, string?, string?, string?, string?, bool, bool, int, TimeSpan, string?, string?, string?, string?, string?, string?, CanonicalPayloadOptions?)

Creates a proof-verifying execution-boundary profile with authoritative host binding expectations.

public static CapabilityGrantValidationOptions CreateBoundExecutionBoundary(CapabilityGrantBindingExpectations bindingExpectations, string? issuer = null, string? audience = null, IEnumerable<string>? scopes = null, DateTimeOffset? validationUtc = null, string? policyVersion = null, string? policyHash = null, string? acknowledgmentId = null, string? handshakeId = null, string? gatewayBinding = null, string? resourceBinding = null, bool requireAcknowledgmentReference = false, bool requireUseCheck = true, int maxUseCount = 1, TimeSpan allowedClockSkew = default, string? expectedProofKeyId = null, string? expectedProofKeyVersion = null, string? expectedProofPolicyVersion = null, string? expectedProofPolicyHash = null, string? requiredProofProvider = null, string? requiredProofHashAlgorithm = null, CanonicalPayloadOptions? proofPayloadOptions = null)

Parameters

bindingExpectations CapabilityGrantBindingExpectations
issuer string
audience string
scopes IEnumerable<string>
validationUtc DateTimeOffset?
policyVersion string
policyHash string
acknowledgmentId string
handshakeId string
gatewayBinding string
resourceBinding string
requireAcknowledgmentReference bool
requireUseCheck bool
maxUseCount int
allowedClockSkew TimeSpan
expectedProofKeyId string
expectedProofKeyVersion string
expectedProofPolicyVersion string
expectedProofPolicyHash string
requiredProofProvider string
requiredProofHashAlgorithm string
proofPayloadOptions CanonicalPayloadOptions

Returns

CapabilityGrantValidationOptions

CreateExecutionBoundary(string?, string?, IEnumerable<string>?, DateTimeOffset?, string?, string?, string?, string?, string?, string?, bool, bool, int, TimeSpan, string?, string?, string?, string?, string?, string?, CanonicalPayloadOptions?)

Obsolete. Retains the legacy execution-boundary signature for binary compatibility and always fails closed.

[Obsolete("CreateExecutionBoundary always fails closed and is retained only for binary compatibility. Use CreateBoundExecutionBoundary(CapabilityGrantBindingExpectations, ...) instead. Planned removal in 8.0.", DiagnosticId = "ASIB901", UrlFormat = "https://asibackbone.github.io/AsiBackbone/articles/capability-grant-hardening.html#legacy-createexecutionboundary-deprecation")]
public static CapabilityGrantValidationOptions CreateExecutionBoundary(string? issuer = null, string? audience = null, IEnumerable<string>? scopes = null, DateTimeOffset? validationUtc = null, string? policyVersion = null, string? policyHash = null, string? acknowledgmentId = null, string? handshakeId = null, string? gatewayBinding = null, string? resourceBinding = null, bool requireAcknowledgmentReference = false, bool requireUseCheck = true, int maxUseCount = 1, TimeSpan allowedClockSkew = default, string? expectedProofKeyId = null, string? expectedProofKeyVersion = null, string? expectedProofPolicyVersion = null, string? expectedProofPolicyHash = null, string? requiredProofProvider = null, string? requiredProofHashAlgorithm = null, CanonicalPayloadOptions? proofPayloadOptions = null)

Parameters

issuer string
audience string
scopes IEnumerable<string>
validationUtc DateTimeOffset?
policyVersion string
policyHash string
acknowledgmentId string
handshakeId string
gatewayBinding string
resourceBinding string
requireAcknowledgmentReference bool
requireUseCheck bool
maxUseCount int
allowedClockSkew TimeSpan
expectedProofKeyId string
expectedProofKeyVersion string
expectedProofPolicyVersion string
expectedProofPolicyHash string
requiredProofProvider string
requiredProofHashAlgorithm string
proofPayloadOptions CanonicalPayloadOptions

Returns

CapabilityGrantValidationOptions

Remarks

This method is retained only for compatibility and always throws InvalidOperationException. Replace calls with CreateBoundExecutionBoundary(CapabilityGrantBindingExpectations, ...), whose required first argument supplies the authoritative subject and optional operation binding. The warning remains non-error in the 7.x line; removal is planned for the next permitted major version.

CreateMetadataValidation(string?, string?, IEnumerable<string>?, DateTimeOffset?, string?, string?, string?, string?, string?, string?, bool, TimeSpan)

public static CapabilityGrantValidationOptions CreateMetadataValidation(string? issuer = null, string? audience = null, IEnumerable<string>? scopes = null, DateTimeOffset? validationUtc = null, string? policyVersion = null, string? policyHash = null, string? acknowledgmentId = null, string? handshakeId = null, string? gatewayBinding = null, string? resourceBinding = null, bool requireAcknowledgmentReference = false, TimeSpan allowedClockSkew = default)

Parameters

issuer string
audience string
scopes IEnumerable<string>
validationUtc DateTimeOffset?
policyVersion string
policyHash string
acknowledgmentId string
handshakeId string
gatewayBinding string
resourceBinding string
requireAcknowledgmentReference bool
allowedClockSkew TimeSpan

Returns

CapabilityGrantValidationOptions

WithExpectedBindings(string?, string?)

Creates a copy with optional host expectations for the authenticated subject and requested operation.

public CapabilityGrantValidationOptions WithExpectedBindings(string? expectedSubjectId = null, string? expectedOperationName = null)

Parameters

expectedSubjectId string
expectedOperationName string

Returns

CapabilityGrantValidationOptions