Reload the key set for tokens signed with an unknown key - #79
Open
robertlemke wants to merge 1 commit into
Open
robertlemke wants to merge 1 commit into
robertlemke wants to merge 1 commit into
Conversation
The authentication provider now loads the JSON Web Key Set of the identity provider again if a token names a key identifier which the cached key set doesn't contain. This also applies to identity tokens received by a refresh. The key set is reloaded at most once per minute, even if the request fails. Previously, the key set was only retrieved when the cache was empty. Identity providers like Microsoft Entra ID rotate their signing keys. Tokens signed with a new key were rejected until the cache entry expired or somebody flushed the cache, and logins failed in the meantime. The minimum interval keeps tokens with made-up key identifiers from flooding the identity provider with requests. Tokens without a key identifier don't trigger a reload, because a failed signature can't tell a rotated key from a forged token in that case. Resolves: #71
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Tokens signed with a key which the identity provider published after the key set was cached are now accepted. If a token names a key identifier ("kid") which the cached JSON Web Key Set doesn't contain, the provider loads the key set again and verifies the signature with it. This also covers identity tokens received by a refresh, which after a rotation are often the first ones signed with the new key.
The key set is reloaded at most once per minute, even if the request fails, so that tokens with made-up key identifiers can't flood the identity provider with requests. Tokens without a key identifier don't trigger a reload.
Resolves #71