Skip to content

Conversation

@PhilipSkinner
Copy link

Added in a the recommended check for validating the time the JWT was issued against the expiry time - probably to deal with machines with different clocks.

Added in the recommended check to ensure there is an algorithm provided in the jose header, though this does not check the signing thumbprint against those that can be read from the well known endpoint.

@jaredhanson jaredhanson added the enhancement New feature or request label Oct 27, 2021
@jaredhanson
Copy link
Owner

This PR isn't diff'ing cleanly. I'll attempt to review this and merge by hand.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants