Class TestJwtAuthority

Namespace
XBullet.EasyTesting.Authentication
Assembly
XBullet.EasyTesting.dll

Creates locally signed JWTs and publishes their OIDC/JWKS metadata in a test host.

public sealed class TestJwtAuthority : IDisposable, ITestScenarioResource
Inheritance
TestJwtAuthority
Implements
Inherited Members

Remarks

The authority owns its generated RSA keys and must be disposed by callers that create it with Create(Action<TestJwtAuthorityOptions>?). Authorities registered with a test factory are owned by that factory.

Properties

CurrentKeyId

Gets the identifier of the key used to sign new tokens.

public string CurrentKeyId { get; }

Property Value

string

The current RSA signing key's non-empty identifier.

DiscoveryRequestCount

Gets the number of discovery requests made through the JWT handler backchannel.

public int DiscoveryRequestCount { get; }

Property Value

int

The request count since construction or the last reset. Direct calls to GetDiscoveryDocument() are not counted.

JwksRequestCount

Gets the number of JWKS requests made through the JWT handler backchannel.

public int JwksRequestCount { get; }

Property Value

int

The request count since construction or the last reset. Direct calls to GetJsonWebKeySet() are not counted.

Options

Gets this authority's configuration.

public TestJwtAuthorityOptions Options { get; }

Property Value

TestJwtAuthorityOptions

The live mutable options instance retained by the authority. It is not a snapshot; callers should finish configuration before using the authority and must not mutate it concurrently.

Methods

CaptureDiagnosticsAsync(CancellationToken)

Captures non-secret authority configuration and request counts.

public ValueTask<object?> CaptureDiagnosticsAsync(CancellationToken cancellationToken = default)

Parameters

cancellationToken CancellationToken

Accepted for the resource contract but not observed because capture completes synchronously. The default token does not request cancellation.

Returns

ValueTask<object>

An already-completed value task containing a newly allocated serializable snapshot with the issuer, audience, current key identifier, and backchannel request counts. It contains no private key material, and the caller may retain it.

Create(Action<TestJwtAuthorityOptions>?)

Creates a standalone local JWT authority.

public static TestJwtAuthority Create(Action<TestJwtAuthorityOptions>? configure = null)

Parameters

configure Action<TestJwtAuthorityOptions>

The callback invoked synchronously once with a new options instance before validation and key generation. When null, all documented option defaults are used. The callback and options argument are not retained separately or invoked concurrently.

Returns

TestJwtAuthority

A new authority that owns its generated signing keys. The caller owns and must dispose it.

CreateExpiredToken(Action<TestJwtBuilder>?)

Creates a locally signed token that is already expired.

public string CreateExpiredToken(Action<TestJwtBuilder>? configure = null)

Parameters

configure Action<TestJwtBuilder>

The callback invoked synchronously once after the not-before time is set to ten minutes ago and expiration to five minutes ago, but before signing. When null, those values remain unchanged; the callback can override either value.

Returns

string

A compact, RSA-SHA256-signed JWT string with the configured expiration.

CreateFutureNotBeforeToken(Action<TestJwtBuilder>?)

Creates a validly signed token that cannot be used until a future time.

public string CreateFutureNotBeforeToken(Action<TestJwtBuilder>? configure = null)

Parameters

configure Action<TestJwtBuilder>

The callback invoked synchronously once after the not-before time is set to five minutes in the future and expiration to ten minutes in the future, but before signing. When null, those values remain unchanged; the callback can override either one.

Returns

string

A compact, RSA-SHA256-signed JWT string with the configured validity interval.

CreateInvalidSignatureToken(Action<TestJwtBuilder>?)

Creates a token whose signature does not match its known key identifier.

public string CreateInvalidSignatureToken(Action<TestJwtBuilder>? configure = null)

Parameters

configure Action<TestJwtBuilder>

The callback invoked synchronously once with a new token builder before signing. When null, default claims are used. The token is signed with a temporary, untrusted RSA key carrying the current trusted key identifier; the callback cannot replace that key and is not retained.

Returns

string

A compact JWT string with a deliberately invalid RSA-SHA256 signature.

CreateToken(Action<TestJwtBuilder>?)

Creates a valid locally signed token.

public string CreateToken(Action<TestJwtBuilder>? configure = null)

Parameters

configure Action<TestJwtBuilder>

The callback invoked synchronously once with a new token builder before signing. When null, the authority's default issuer, audience, lifetime, and claims are used. The callback and builder are not retained or invoked concurrently.

Returns

string

A compact, RSA-SHA256-signed JWT string.

CreateUnknownKeyToken(Action<TestJwtBuilder>?)

Creates a signed token with a key identifier absent from JWKS.

public string CreateUnknownKeyToken(Action<TestJwtBuilder>? configure = null)

Parameters

configure Action<TestJwtBuilder>

The callback invoked synchronously once with a new token builder before signing. When null, default claims are used. The token is signed with a temporary, untrusted RSA key whose identifier is not published; the callback cannot replace that key and is not retained.

Returns

string

A compact, RSA-SHA256-signed JWT string whose key is absent from this authority's JWKS.

CreateUnsignedToken(Action<TestJwtBuilder>?)

Creates an unsigned token.

public string CreateUnsignedToken(Action<TestJwtBuilder>? configure = null)

Parameters

configure Action<TestJwtBuilder>

The callback invoked synchronously once with a new token builder before serialization. When null, the authority's default issuer, audience, lifetime, and claims are used. The callback and builder are not retained or invoked concurrently.

Returns

string

A compact JWT string with no signing credentials.

CreateWrongAudienceToken(Action<TestJwtBuilder>?)

Creates a locally signed token with an invalid audience.

public string CreateWrongAudienceToken(Action<TestJwtBuilder>? configure = null)

Parameters

configure Action<TestJwtBuilder>

The callback invoked synchronously once after the audience is changed to the configured audience plus -wrong, but before signing. When null, that invalid audience remains; the callback can replace it.

Returns

string

A compact, RSA-SHA256-signed JWT string with the configured audience.

CreateWrongIssuerToken(Action<TestJwtBuilder>?)

Creates a locally signed token with an invalid issuer.

public string CreateWrongIssuerToken(Action<TestJwtBuilder>? configure = null)

Parameters

configure Action<TestJwtBuilder>

The callback invoked synchronously once after the issuer is changed by appending /wrong, but before signing. When null, that invalid issuer remains; the callback can replace it.

Returns

string

A compact, RSA-SHA256-signed JWT string with the configured issuer.

Dispose()

Releases every RSA key owned by this authority.

public void Dispose()

Remarks

Calling this method more than once has no effect.

GetDiscoveryDocument()

Gets an OIDC discovery document suitable for JSON serialization.

public object GetDiscoveryDocument()

Returns

object

A newly allocated object containing the configured issuer, JWKS URI, and RSA-SHA256 signing algorithm. The caller may retain the returned object.

GetJsonWebKeySet()

Gets the authority's public signing key as a JWKS document.

public object GetJsonWebKeySet()

Returns

object

A newly allocated JWKS-shaped object containing snapshots of every currently published public RSA key. It contains no private key material, and the caller may retain it.

ResetAsync(CancellationToken)

Replaces all signing keys and clears the backchannel request counters.

public ValueTask ResetAsync(CancellationToken cancellationToken = default)

Parameters

cancellationToken CancellationToken

Accepted for the resource contract but not observed because reset completes synchronously. The default token does not request cancellation.

Returns

ValueTask

A value task that is already complete after the reset side effects finish.

RotateSigningKey(bool)

Rotates the signing key and returns its identifier. Previous public keys can optionally remain in JWKS.

public string RotateSigningKey(bool retainPreviousKey = false)

Parameters

retainPreviousKey bool

true to continue publishing all prior public keys so existing tokens can still be validated; false to publish only the new key. The default is false.

Returns

string

The non-empty identifier of the newly generated RSA signing key.