ProtectedconstructorProtectedBaseThe contained client+server engine that owns all cached claim-type metadata.
All loaded Identity Claim Types
The metadata provider this engine operates under.
This class is a process-wide singleton (BaseSingleton keys on class name), so it cannot
own a provider the way a BaseEngine subclass does — one instance serves every connection
in the process. Callers that have a request-scoped provider should pass it explicitly to
the method they are calling; this settable accessor exists for hosts that bind one at
startup, and falls back to the global default only when nothing has been supplied.
Same shape as AIEngine.Provider — which QueryEngineServer and ComponentMetadataEngineServer
both cite as the pattern to follow — and structurally exempt from the multi-provider
compliance scanner, so it needs no global-provider-ok suppression.
StaticInstanceDiscovers every pending claim addressed to the authenticated user's email and redeems each one. This is workflow #2 from the entity's migration header — "Automatic Claim on Login".
Server-only, and deliberately so: it runs through RedeemClaim, so each redemption still
passes the full gate (email match or verified token, atomic CAS, driver exception handling).
The email filter used to find the claims is a lookup convenience, not the security boundary.
Optionaloptions: RedeemClaimOptionsEnsures metadata is configured and loaded
OptionalforceRefresh: booleanOptionalcontextUser: UserInfoOptionalprovider: IMetadataProviderCreates and saves an IdentityClaim record, sends an email notification via the MJ Communications framework if configured, and executes the driver's OnCreate lifecycle method.
OptionalcontextUser: UserInfoOptionalprovider: IMetadataProviderFinds a claim type by name (case-insensitive)
Parses a claim type's Configuration JSON into the engine-recognized shape
Resolves the concrete BaseIdentityClaimDriver instance for a given claim type
The Global Object Store is a place to store global objects that need to be shared across the application. Depending on the execution environment, this could be the window object in a browser, or the global object in a node environment, or something else in other contexts. The key here is that in some cases static variables are not truly shared because it is possible that a given class might have copies of its code in multiple paths in a deployed application. This approach ensures that no matter how many code copies might exist, there is only one instance of the object in question by using the Global Object Store.
Fetches all pending, unexpired claims for a normalized email address.
OptionalcontextUser: UserInfoOptionalprovider: IMetadataProviderNormalizes email address (trimmed, lowercase)
Redeems a claim for an authenticated user, running the driver's OnClaim implementation.
Authorization is email match OR verified token. The email-match path is additionally
gated by RedeemClaimOptions.EmailVerified and the claim type's
Configuration (RequireVerifiedEmail / RequireToken) — see RedeemClaimOptions.
Optionaltoken: stringOptionaloptions: RedeemClaimOptionsRevokes a pending claim and invokes the driver's OnRevoke lifecycle method.
OptionalcontextUser: UserInfoOptionalprovider: IMetadataProviderProtected StaticgetReturns the singleton instance of the class. If the instance does not exist, it is created and stored in the Global Object Store. If className is provided it will be used as part of the key in the Global Object Store, otherwise the actual class name will be used. NOTE: the class name used by default is the lowest level of the object hierarchy, so if you have a class that extends another class, the lowest level class name will be used.
OptionalclassName: string
Server-side Identity Claim engine — the ONLY place the claim lifecycle is implemented.
Uses containment rather than inheritance, the same split as
AIEngine/AIEngineBase: an instance of the client+serverIdentityClaimEngineis held via Base and its cached members (claim types, lookups, driver resolution, email normalization) are proxied below, soIdentityClaimEngineServer.Instance.Xreaches the whole surface. When a public member is added toIdentityClaimEngine, add a proxy here.Creation, redemption and revocation live here and nowhere else, because each depends on something a browser cannot do:
crypto.randomBytestoken generation and SHA-256 hashing,timingSafeEqualcomparison, an atomic compare-and-swap issued as raw SQL, and email dispatch via MJ Communications.Description
ONLY USE ON SERVER-SIDE. For claim-type metadata only, use
IdentityClaimEngine, which is safe in any host.