Skip to content

v0.73.0

Choose a tag to compare

@github-actions github-actions released this 17 Sep 00:29
· 108 commits to main since this release

Changed

  • One rule decides which key verifies a token, on every path, and one
    reason says when no key does. The kid names the key: the key declaring
    it, or a key declaring no kid at all, since a key published without a name
    can be reached no other way. A token carrying no kid leaves the choice
    to the set, which only a set holding exactly one key can make. Anything
    else, a kid the set does not hold or a choice between keys, is
    jwt.ErrUnknownKey, reason unknown_key.

    On the JWKS path this removes a fallback. A kid that matched nothing was
    tried against every key of the set in turn, so a token could name one key
    and be admitted by another: a claim about the issuer's set that the issuer
    never made. A kid miss still forces one refresh of the set first, so a key
    just rotated in at the issuer is picked up rather than refused. A
    single-key set, which is what the family's issuers serve, is otherwise
    unchanged.

    On the local path this changes a reason. A token of Config.LocalIssuer
    naming a kid the local set does not hold was ErrInvalidSignature, which
    said a signature had failed when no key had been asked.

    Once the key is chosen, only its own verdict counts: a signature that does
    not check out against it is ErrInvalidSignature and not the other
    refusal, so the key a rotation replaced does not get to verify in the
    newer key's place. A caller that relied on the fallback sees unknown_key
    where it saw invalid signature. Both are refusals, so nothing that was
    admitted before is refused now except a token naming a key nobody
    published, and nothing that was refused is admitted.