Class TestJwtAuthority
- Namespace
- XBullet.EasyTesting.Authentication
- Assembly
- XBullet.EasyTesting.dll
Creates locally signed JWTs and publishes their OIDC/JWKS metadata in a test host.
public sealed class TestJwtAuthority : IDisposable, ITestScenarioResource
- Inheritance
-
TestJwtAuthority
- Implements
- Inherited Members
Remarks
The authority owns its generated RSA keys and must be disposed by callers that create it with Create(Action<TestJwtAuthorityOptions>?). Authorities registered with a test factory are owned by that factory.
Properties
CurrentKeyId
Gets the identifier of the key used to sign new tokens.
public string CurrentKeyId { get; }
Property Value
- string
The current RSA signing key's non-empty identifier.
DiscoveryRequestCount
Gets the number of discovery requests made through the JWT handler backchannel.
public int DiscoveryRequestCount { get; }
Property Value
- int
The request count since construction or the last reset. Direct calls to GetDiscoveryDocument() are not counted.
JwksRequestCount
Gets the number of JWKS requests made through the JWT handler backchannel.
public int JwksRequestCount { get; }
Property Value
- int
The request count since construction or the last reset. Direct calls to GetJsonWebKeySet() are not counted.
Options
Gets this authority's configuration.
public TestJwtAuthorityOptions Options { get; }
Property Value
- TestJwtAuthorityOptions
The live mutable options instance retained by the authority. It is not a snapshot; callers should finish configuration before using the authority and must not mutate it concurrently.
Methods
CaptureDiagnosticsAsync(CancellationToken)
Captures non-secret authority configuration and request counts.
public ValueTask<object?> CaptureDiagnosticsAsync(CancellationToken cancellationToken = default)
Parameters
cancellationTokenCancellationTokenAccepted for the resource contract but not observed because capture completes synchronously. The default token does not request cancellation.
Returns
- ValueTask<object>
An already-completed value task containing a newly allocated serializable snapshot with the issuer, audience, current key identifier, and backchannel request counts. It contains no private key material, and the caller may retain it.
Create(Action<TestJwtAuthorityOptions>?)
Creates a standalone local JWT authority.
public static TestJwtAuthority Create(Action<TestJwtAuthorityOptions>? configure = null)
Parameters
configureAction<TestJwtAuthorityOptions>The callback invoked synchronously once with a new options instance before validation and key generation. When null, all documented option defaults are used. The callback and options argument are not retained separately or invoked concurrently.
Returns
- TestJwtAuthority
A new authority that owns its generated signing keys. The caller owns and must dispose it.
CreateExpiredToken(Action<TestJwtBuilder>?)
Creates a locally signed token that is already expired.
public string CreateExpiredToken(Action<TestJwtBuilder>? configure = null)
Parameters
configureAction<TestJwtBuilder>The callback invoked synchronously once after the not-before time is set to ten minutes ago and expiration to five minutes ago, but before signing. When null, those values remain unchanged; the callback can override either value.
Returns
- string
A compact, RSA-SHA256-signed JWT string with the configured expiration.
CreateFutureNotBeforeToken(Action<TestJwtBuilder>?)
Creates a validly signed token that cannot be used until a future time.
public string CreateFutureNotBeforeToken(Action<TestJwtBuilder>? configure = null)
Parameters
configureAction<TestJwtBuilder>The callback invoked synchronously once after the not-before time is set to five minutes in the future and expiration to ten minutes in the future, but before signing. When null, those values remain unchanged; the callback can override either one.
Returns
- string
A compact, RSA-SHA256-signed JWT string with the configured validity interval.
CreateInvalidSignatureToken(Action<TestJwtBuilder>?)
Creates a token whose signature does not match its known key identifier.
public string CreateInvalidSignatureToken(Action<TestJwtBuilder>? configure = null)
Parameters
configureAction<TestJwtBuilder>The callback invoked synchronously once with a new token builder before signing. When null, default claims are used. The token is signed with a temporary, untrusted RSA key carrying the current trusted key identifier; the callback cannot replace that key and is not retained.
Returns
- string
A compact JWT string with a deliberately invalid RSA-SHA256 signature.
CreateToken(Action<TestJwtBuilder>?)
Creates a valid locally signed token.
public string CreateToken(Action<TestJwtBuilder>? configure = null)
Parameters
configureAction<TestJwtBuilder>The callback invoked synchronously once with a new token builder before signing. When null, the authority's default issuer, audience, lifetime, and claims are used. The callback and builder are not retained or invoked concurrently.
Returns
- string
A compact, RSA-SHA256-signed JWT string.
CreateUnknownKeyToken(Action<TestJwtBuilder>?)
Creates a signed token with a key identifier absent from JWKS.
public string CreateUnknownKeyToken(Action<TestJwtBuilder>? configure = null)
Parameters
configureAction<TestJwtBuilder>The callback invoked synchronously once with a new token builder before signing. When null, default claims are used. The token is signed with a temporary, untrusted RSA key whose identifier is not published; the callback cannot replace that key and is not retained.
Returns
- string
A compact, RSA-SHA256-signed JWT string whose key is absent from this authority's JWKS.
CreateUnsignedToken(Action<TestJwtBuilder>?)
Creates an unsigned token.
public string CreateUnsignedToken(Action<TestJwtBuilder>? configure = null)
Parameters
configureAction<TestJwtBuilder>The callback invoked synchronously once with a new token builder before serialization. When null, the authority's default issuer, audience, lifetime, and claims are used. The callback and builder are not retained or invoked concurrently.
Returns
- string
A compact JWT string with no signing credentials.
CreateWrongAudienceToken(Action<TestJwtBuilder>?)
Creates a locally signed token with an invalid audience.
public string CreateWrongAudienceToken(Action<TestJwtBuilder>? configure = null)
Parameters
configureAction<TestJwtBuilder>The callback invoked synchronously once after the audience is changed to the configured audience plus
-wrong, but before signing. When null, that invalid audience remains; the callback can replace it.
Returns
- string
A compact, RSA-SHA256-signed JWT string with the configured audience.
CreateWrongIssuerToken(Action<TestJwtBuilder>?)
Creates a locally signed token with an invalid issuer.
public string CreateWrongIssuerToken(Action<TestJwtBuilder>? configure = null)
Parameters
configureAction<TestJwtBuilder>The callback invoked synchronously once after the issuer is changed by appending
/wrong, but before signing. When null, that invalid issuer remains; the callback can replace it.
Returns
- string
A compact, RSA-SHA256-signed JWT string with the configured issuer.
Dispose()
Releases every RSA key owned by this authority.
public void Dispose()
Remarks
Calling this method more than once has no effect.
GetDiscoveryDocument()
Gets an OIDC discovery document suitable for JSON serialization.
public object GetDiscoveryDocument()
Returns
- object
A newly allocated object containing the configured issuer, JWKS URI, and RSA-SHA256 signing algorithm. The caller may retain the returned object.
GetJsonWebKeySet()
Gets the authority's public signing key as a JWKS document.
public object GetJsonWebKeySet()
Returns
- object
A newly allocated JWKS-shaped object containing snapshots of every currently published public RSA key. It contains no private key material, and the caller may retain it.
ResetAsync(CancellationToken)
Replaces all signing keys and clears the backchannel request counters.
public ValueTask ResetAsync(CancellationToken cancellationToken = default)
Parameters
cancellationTokenCancellationTokenAccepted for the resource contract but not observed because reset completes synchronously. The default token does not request cancellation.
Returns
- ValueTask
A value task that is already complete after the reset side effects finish.
RotateSigningKey(bool)
Rotates the signing key and returns its identifier. Previous public keys can optionally remain in JWKS.
public string RotateSigningKey(bool retainPreviousKey = false)
Parameters
retainPreviousKeybooltrue to continue publishing all prior public keys so existing tokens can still be validated; false to publish only the new key. The default is false.
Returns
- string
The non-empty identifier of the newly generated RSA signing key.