feat(hono/jwk): Extended with allow_anon
option & passing Context
to callbacks
#3961
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Adding two main useful features people have been asking for in the original PR + some slight changes.
New features:
allow_anon
option totrue
jwks_uri
instead of only a hard-coded stringContext
is now included in all callbacks, so you can e.g pull information fromc.env
such as auth serverExample:
Note 1: This PR allows having a single endpoint for both authenticated and non-authenticated requests through
allow_anon
. The variablec.get("jwtPayload")
can be used to differentiate authenticated requests from anonymous requests since hono requires requests to haveexp
andiat
in the payload (in theverify
stage) which means the payload would always be defined for authenticated requests and be reliably used as indicator.Note 2: Setting
allow_anon
totrue
means requests without a token present (in either header/cookie) would be allowed to pass through the middleware successfully.Tests: Added 3 extra tests + modified one test to cover
jwks_uri
being a function.This PR breaks no code at all except for
Jwt.verifyFromJwks(...)
—specifically removed callbacks support from it since they're redundant and can be called outside, and also since only the middleware can provide theContext
variable to the callbacks.