Table of Contents

Class InMemoryCapabilityGrantUseStore

Namespace
AsiBackbone.Storage.InMemory.CapabilityGrants
Assembly
AsiBackbone.Storage.InMemory.dll

Provides a non-durable, in-process capability grant use store for tests, samples, and local validation.

public sealed class InMemoryCapabilityGrantUseStore : ICapabilityGrantUseStore
Inheritance
InMemoryCapabilityGrantUseStore
Implements
Inherited Members

Remarks

This store is thread-safe within a single process, but it is not durable, distributed, replicated, or suitable for production replay protection. Hosts that require production single-use or bounded-use guarantees should provide a durable implementation of ICapabilityGrantUseStore with documented transaction, locking, retention, and failure semantics.

Use records are retained until a grant has been expired for longer than EvictionGracePeriod, measured against the latest use time this store has observed. A grant past that retention horizon is refused with capability.use-retention-elapsed rather than given a fresh count, because its earlier uses may already have been evicted. Set EvictionGracePeriod to at least the largest AllowedClockSkew any validator uses with this store; otherwise grants that are expired but still inside the validator's skew are denied (fail closed) instead of accepted.

Properties

EvictionGracePeriod

Gets or sets the grace period retained after a grant expires before its use record may be evicted.

public TimeSpan EvictionGracePeriod { get; set; }

Property Value

TimeSpan

Remarks

Defaults to five minutes. This is also the retention horizon: a grant expired for longer than this period is refused rather than consumed. Set it to at least the largest AllowedClockSkew used with this store.

Exceptions

ArgumentOutOfRangeException

The value is negative.

Methods

CancelGrant(string)

Marks a grant identifier as cancelled for every issuer, for subsequent local validation attempts.

public void CancelGrant(string grantId)

Parameters

grantId string

The stable capability grant identifier.

Remarks

Use records are keyed by issuer and token identifier, so this overload cancels every issuer's grant that uses the identifier. Call CancelGrant(string, string) to cancel one issuer's grant.

CancelGrant(string, string)

Marks one issuer's grant as cancelled for subsequent local validation attempts.

public void CancelGrant(string issuer, string grantId)

Parameters

issuer string

The grant issuer.

grantId string

The stable capability grant identifier.

Clear()

Clears use-count, stopped/cancelled, and observed-time state from this in-memory store instance.

public void Clear()

GetUseCount(string)

Gets the observed use count for a grant identifier, across every issuer that used it.

public int GetUseCount(string grantId)

Parameters

grantId string

The stable capability grant identifier.

Returns

int

The observed use count, or zero when the grant has not been consumed by this store instance.

Remarks

Use records are keyed by issuer and token identifier, so this overload sums the issuers that used the identifier. Call GetUseCount(string, string) to read one issuer's count.

GetUseCount(string, string)

Gets the observed use count for one issuer's grant identifier.

public int GetUseCount(string issuer, string grantId)

Parameters

issuer string

The grant issuer.

grantId string

The stable capability grant identifier.

Returns

int

The observed use count, or zero when that issuer's grant has not been consumed by this store instance.

StopGrant(string)

Marks a grant identifier as stopped for every issuer, for subsequent local validation attempts.

public void StopGrant(string grantId)

Parameters

grantId string

The stable capability grant identifier.

Remarks

Use records are keyed by issuer and token identifier, so this overload stops every issuer's grant that uses the identifier. Call StopGrant(string, string) to stop one issuer's grant.

StopGrant(string, string)

Marks one issuer's grant as stopped for subsequent local validation attempts.

public void StopGrant(string issuer, string grantId)

Parameters

issuer string

The grant issuer.

grantId string

The stable capability grant identifier.

TryConsumeAsync(CapabilityGrant, int, DateTimeOffset, CancellationToken)

Checks whether the grant can be used and consumes one use when accepted.

public ValueTask<CapabilityGrantUseResult> TryConsumeAsync(CapabilityGrant grant, int maxUseCount, DateTimeOffset usedUtc, CancellationToken cancellationToken = default)

Parameters

grant CapabilityGrant

The capability grant being validated.

maxUseCount int

The maximum allowed use count for the validation context.

usedUtc DateTimeOffset

The UTC timestamp for this use attempt.

cancellationToken CancellationToken

A token used to observe cancellation.

Returns

ValueTask<CapabilityGrantUseResult>

The use-control result.