-
Notifications
You must be signed in to change notification settings - Fork 487
[ENHANCEMENT] Validation without introspect #2915
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Conversation
felixauringer
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I have not built it myself but the code looks good. I like that aud validation is now part of the usual verification flow.
There is still an additional check in the introspection case here. Do you think that one is still necessary? I think the new check from this PR is also used in the introspection case as part of the local validation anyway.
|
Thanks @felixauringer for the review I pushed a little commit to polish the doc |
Thanks, the docs look good to me now 🙂 I am still unsure about the double aud validation mentioned above. |
I fear I do not get you. What do you mean? |
|
When using introspection, there are currently two places with aud checks:
I am not sure whether the second is still needed. As far as I see it, the signature verification - which now also includes the aud check - is done in every code path anyway. |
Fair |
|
While I'm at it it seems less relevant to mandate introspect. Would you agree relaxing it @felixauringer ? |
No description provided.