Repository navigation
v0.73.0
Changed
-
One rule decides which key verifies a token, on every path, and one
reason says when no key does. Thekidnames the key: the key declaring
it, or a key declaring no kid at all, since a key published without a name
can be reached no other way. A token carrying nokidleaves the choice
to the set, which only a set holding exactly one key can make. Anything
else, a kid the set does not hold or a choice between keys, is
jwt.ErrUnknownKey, reasonunknown_key.On the JWKS path this removes a fallback. A kid that matched nothing was
tried against every key of the set in turn, so a token could name one key
and be admitted by another: a claim about the issuer's set that the issuer
never made. A kid miss still forces one refresh of the set first, so a key
just rotated in at the issuer is picked up rather than refused. A
single-key set, which is what the family's issuers serve, is otherwise
unchanged.On the local path this changes a reason. A token of
Config.LocalIssuer
naming a kid the local set does not hold wasErrInvalidSignature, which
said a signature had failed when no key had been asked.Once the key is chosen, only its own verdict counts: a signature that does
not check out against it isErrInvalidSignatureand not the other
refusal, so the key a rotation replaced does not get to verify in the
newer key's place. A caller that relied on the fallback seesunknown_key
where it sawinvalid signature. Both are refusals, so nothing that was
admitted before is refused now except a token naming a key nobody
published, and nothing that was refused is admitted.