Bump github.com/MicahParks/keyfunc from 1.5.1 to 1.9.0
Bumps [github.com/MicahParks/keyfunc](https://github.com/MicahParks/keyfunc) from 1.5.1 to 1.9.0. - [Release notes](https://github.com/MicahParks/keyfunc/releases) - [Commits](https://github.com/MicahParks/keyfunc/compare/v1.5.1...v1.9.0) --- updated-dependencies: - dependency-name: github.com/MicahParks/keyfunc dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
This commit is contained in:
committed by
Ralf Haferkamp
parent
3f40a42bb2
commit
71e548189d
+13
-5
@@ -70,7 +70,7 @@ jwksURL := os.Getenv("JWKS_URL")
|
||||
|
||||
// Confirm the environment variable is not empty.
|
||||
if jwksURL == "" {
|
||||
log.Fatalln("JWKS_URL environment variable must be populated.")
|
||||
log.Fatalln("JWKS_URL environment variable must be populated.")
|
||||
}
|
||||
```
|
||||
|
||||
@@ -81,7 +81,7 @@ Via HTTP:
|
||||
// Create the JWKS from the resource at the given URL.
|
||||
jwks, err := keyfunc.Get(jwksURL, keyfunc.Options{}) // See recommended options in the examples directory.
|
||||
if err != nil {
|
||||
log.Fatalf("Failed to get the JWKS from the given URL.\nError: %s", err)
|
||||
log.Fatalf("Failed to get the JWKS from the given URL.\nError: %s", err)
|
||||
}
|
||||
```
|
||||
Via JSON:
|
||||
@@ -92,7 +92,7 @@ var jwksJSON = json.RawMessage(`{"keys":[{"kid":"zXew0UJ1h6Q4CCcd_9wxMzvcp5cEBif
|
||||
// Create the JWKS from the resource at the given URL.
|
||||
jwks, err := keyfunc.NewJSON(jwksJSON)
|
||||
if err != nil {
|
||||
log.Fatalf("Failed to create JWKS from JSON.\nError: %s", err)
|
||||
log.Fatalf("Failed to create JWKS from JSON.\nError: %s", err)
|
||||
}
|
||||
```
|
||||
Via a given key:
|
||||
@@ -103,7 +103,7 @@ uniqueKeyID := "myKeyID"
|
||||
|
||||
// Create the JWKS from the HMAC key.
|
||||
jwks := keyfunc.NewGiven(map[string]keyfunc.GivenKey{
|
||||
uniqueKeyID: keyfunc.NewGivenHMAC(key),
|
||||
uniqueKeyID: keyfunc.NewGivenHMAC(key),
|
||||
})
|
||||
```
|
||||
|
||||
@@ -117,7 +117,7 @@ features mentioned at the bottom of this `README.md`.
|
||||
// Parse the JWT.
|
||||
token, err := jwt.Parse(jwtB64, jwks.Keyfunc)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("failed to parse token: %w", err)
|
||||
return nil, fmt.Errorf("failed to parse token: %w", err)
|
||||
}
|
||||
```
|
||||
|
||||
@@ -170,6 +170,9 @@ These features can be configured by populating fields in the
|
||||
* Custom cryptographic algorithms can be used. Make sure to
|
||||
use [`jwt.RegisterSigningMethod`](https://pkg.go.dev/github.com/golang-jwt/jwt/v4#RegisterSigningMethod) before
|
||||
parsing JWTs. For an example, see the `examples/custom` directory.
|
||||
* The remote JWKS resource can be refreshed manually using the `.Refresh` method. This can bypass the rate limit, if the
|
||||
option is set.
|
||||
* There is support for creating one `jwt.Keyfunc` from multiple JWK Sets through the use of the `keyfunc.GetMultiple`.
|
||||
|
||||
## Notes
|
||||
Trailing padding is required to be removed from base64url encoded keys inside a JWKS. This is because RFC 7517 defines
|
||||
@@ -180,6 +183,11 @@ base64url the same as RFC 7515 Section 2:
|
||||
However, this package will remove trailing padding on base64url encoded keys to account for improper implementations of
|
||||
JWKS.
|
||||
|
||||
This package will check the `alg` in each JWK. If present, it will confirm the same `alg` is in a given JWT's header
|
||||
before returning the key for signature verification. If the `alg`s do not match, `keyfunc.ErrJWKAlgMismatch` will
|
||||
prevent the key being used for signature verification. If the `alg` is not present in the JWK, this check will not
|
||||
occur.
|
||||
|
||||
## References
|
||||
This project was built and tested using various RFCs and services. The services are listed below:
|
||||
* [Keycloak](https://www.keycloak.org/)
|
||||
|
||||
Reference in New Issue
Block a user