Table of Contents

Interface IAuthorizationService

Namespace
Microsoft.ServiceHub.Framework.Services
Assembly
Microsoft.ServiceHub.Framework.dll

The service contract for the Authorization service.

[JsonRpcContract]
[GenerateShape(IncludeMethods = MethodShapeFlags.PublicInstance)]
[TypeShapeProvider(typeof(IAuthorizationService.__LocalTypeShapeProvider__))]
[JsonRpcProxyMapping(typeof(Microsoft_ServiceHub_Framework_Services_IAuthorizationService_Proxy))]
public interface IAuthorizationService
Extension Methods

Remarks

For improved performance, clients may pass an instance of this interface to AuthorizationServiceClient and use that so that queries are locally cached.

Methods

CheckAuthorizationAsync(ProtectedOperation, CancellationToken)

Checks whether a previously authenticated user is authorized to perform some operation.

ValueTask<bool> CheckAuthorizationAsync(ProtectedOperation operation, CancellationToken cancellationToken = default)

Parameters

operation ProtectedOperation

The operation to be performed.

cancellationToken CancellationToken

A cancellation token.

Returns

ValueTask<bool>

true if the client is authorized to perform the operation; false otherwise.

GetCredentialsAsync(CancellationToken)

Gets the data to include in the ClientCredentials property of a service request.

ValueTask<IReadOnlyDictionary<string, string>> GetCredentialsAsync(CancellationToken cancellationToken = default)

Parameters

cancellationToken CancellationToken

A cancellation token.

Returns

ValueTask<IReadOnlyDictionary<string, string>>

A set of credentials.

Remarks

If this service was created with credentials in ClientCredentials, this method will return that same set or perhaps a refreshed set representing the same client. If this service was created without credentials, credentials are obtained from the identity running the process hosting this service.

Exceptions

UnauthorizedAccessException

Thrown when credentials are not available, are expired beyond recovery, or revoked.

Events

AuthorizationChanged

Occurs when the client's set of authorized activities has changed. Clients that have cached previous authorization responses should invalidate the cache.

event EventHandler AuthorizationChanged

Event Type

EventHandler

CredentialsChanged

Occurs when the credentials previously supplied to this service are at or near expiry.

event EventHandler CredentialsChanged

Event Type

EventHandler

Remarks

Handlers should request a fresh set of credentials with GetCredentialsAsync(CancellationToken) to keep this service current and to include in future requests for other services.