Abblix.SecurityEvents.MinimalAPI
2.4.0
Prefix Reserved
dotnet add package Abblix.SecurityEvents.MinimalAPI --version 2.4.0
NuGet\Install-Package Abblix.SecurityEvents.MinimalAPI -Version 2.4.0
<PackageReference Include="Abblix.SecurityEvents.MinimalAPI" Version="2.4.0" />
<PackageVersion Include="Abblix.SecurityEvents.MinimalAPI" Version="2.4.0" />
<PackageReference Include="Abblix.SecurityEvents.MinimalAPI" />
paket add Abblix.SecurityEvents.MinimalAPI --version 2.4.0
#r "nuget: Abblix.SecurityEvents.MinimalAPI, 2.4.0"
#:package Abblix.SecurityEvents.MinimalAPI@2.4.0
#addin nuget:?package=Abblix.SecurityEvents.MinimalAPI&version=2.4.0
#tool nuget:?package=Abblix.SecurityEvents.MinimalAPI&version=2.4.0
Abblix.SecurityEvents.MinimalAPI
ASP.NET Core Minimal API integration for Abblix.SecurityEvents. It maps the endpoints that
receive a token and nothing more: MapBackChannelLogoutEndpoint for OpenID Connect Back-Channel
Logout 1.0, and MapPushDeliveryEndpoint for RFC 8935 push delivery. The request and response rules
live in the core, so this package is the transport and the route pattern.
Shared Signals in .NET: SSF, CAEP, RISC and Back-Channel Logout walks the smallest path through the whole stack: a relying party that wants logout notifications, installs this adapter and its core, and never meets a stream.
Which adapter maps which endpoint
There are two Minimal API packages in this family, and the line between them is not the one that first suggests itself. It is not receiver here and transmitter there: the Shared Signals package holds receiver-role code of its own - the stream management client, the transmitter discovery client. The question that decides placement is whether the endpoint stops making sense without a stream:
- Back-Channel Logout: one token, delivered once, from a provider the relying party already knows through OpenID Connect. Nothing was negotiated, nothing was subscribed to. Here.
- Push delivery: "accept a SET at this address" (RFC 8935 Section 2.1). The URL is the receiver's own and carries no stream identity; a receiver can be handed events by a counterparty known from anywhere. Here.
- Stream management, status, subjects, verification, the
ssf-configurationdocument and the transmitter's poll endpoint - each is meaningless without a stream, and the poll address is addressed by stream identifier. Those live in Abblix.SharedSignals.MinimalAPI.
Push and poll are one pair of specifications (RFC 8935 and RFC 8936) and still land in two packages, which surprises people. The line between them is the address. A push intake accepts a token and needs to know nothing about streams, so it is here. A poll endpoint serves one stream's queue and is addressed by stream identifier, so it is over there.
The practical consequence is why the split is kept: a relying party that wants only Back-Channel Logout takes this package and nothing else. Folding the two together would put the whole Shared Signals public surface in front of every such host, none of which will ever call it.
Use
builder.Services.AddSecurityEvents();
builder.Services.AddJwksKeyResolution(options =>
options.JwksUris["https://op.example.com"] = new Uri("https://op.example.com/.well-known/jwks"));
builder.Services.AddBackChannelLogoutReceiver(new BackChannelLogoutValidationOptions
{
ExpectedIssuers = ["https://op.example.com"],
ExpectedAudience = "this-client-id",
});
// Ends the sessions a validated notification names - the half only the application can write.
builder.Services.AddSingleton<ILogoutNotificationSink, MySessionStore>();
app.MapBackChannelLogoutEndpoint("/backchannel-logout");
The route is whatever the client registered with its provider as backchannel_logout_uri.
What the host still owns
- Where the sessions are. Section 2.7 makes locating and clearing them the relying party's, because only it knows where it keeps them. That is the sink above.
- Which keys to trust. Key resolution is deployment knowledge, so the core asks for it rather than guessing.
- Resilience and timeouts of anything fetched outward, through
IHttpClientFactoryas usual.
Part of the Abblix product family
Abblix.SecurityEvents.MinimalAPI is the ASP.NET Core adapter of Abblix.SecurityEvents, which owns the token and the wire. Event streams and their management layer live in Abblix.SharedSignals, and the identity provider that emits these events is Abblix OIDC Server.
License
Abblix.SecurityEvents.MinimalAPI is licensed under the Apache License 2.0.
Contacts
- General inquiries: info@abblix.com
- Support and security reports: support@abblix.com
- Website: Abblix OIDC Server
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 is compatible. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Abblix.SecurityEvents (>= 2.4.0)
-
net8.0
- Abblix.SecurityEvents (>= 2.4.0)
- Microsoft.Extensions.Caching.Abstractions (>= 10.0.8)
- Microsoft.Extensions.Configuration (>= 10.0.8)
- Microsoft.Extensions.Configuration.Binder (>= 10.0.8)
- Microsoft.Extensions.DependencyInjection (>= 10.0.8)
- Microsoft.Extensions.DependencyInjection.Abstractions (>= 10.0.8)
- Microsoft.Extensions.Hosting.Abstractions (>= 10.0.8)
- Microsoft.Extensions.Http (>= 10.0.8)
- Microsoft.Extensions.Logging (>= 10.0.8)
- Microsoft.Extensions.Logging.Abstractions (>= 10.0.8)
- Microsoft.Extensions.Options (>= 10.0.8)
- System.Linq.Async (>= 7.0.1)
-
net9.0
- Abblix.SecurityEvents (>= 2.4.0)
- Microsoft.Extensions.Caching.Abstractions (>= 10.0.8)
- Microsoft.Extensions.Configuration (>= 10.0.8)
- Microsoft.Extensions.Configuration.Binder (>= 10.0.8)
- Microsoft.Extensions.DependencyInjection (>= 10.0.8)
- Microsoft.Extensions.DependencyInjection.Abstractions (>= 10.0.8)
- Microsoft.Extensions.Hosting.Abstractions (>= 10.0.8)
- Microsoft.Extensions.Http (>= 10.0.8)
- Microsoft.Extensions.Logging (>= 10.0.8)
- Microsoft.Extensions.Logging.Abstractions (>= 10.0.8)
- Microsoft.Extensions.Options (>= 10.0.8)
- System.Linq.Async (>= 7.0.1)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 2.4.0 | 43 | 9/5/2026 |
The intake side of security events as route handlers: the OpenID Back-Channel Logout endpoint a relying party exposes, and the push delivery endpoint of RFC 8935 that a transmitter posts to. Each validates the token through the Security Events core before handing it on, answers with the status codes the specifications prescribe, and needs no MVC framework in the host. Full details: https://github.com/Abblix/Oidc.Server/releases/tag/v2.4