Uploaded image for project: 'AeroGear'
  1. AeroGear
  2. AEROGEAR-2091

Implement a function to check the Integrity of the Identity/Access Token

    XMLWordPrintable

Details

    • Task
    • Resolution: Done
    • Major
    • None
    • None
    • None

    Description

      What

      • Implement the function. It should be similar to the Android implementation
      • It should have unit tests
      • The example app should be updated to allow verify the implementation

      Progress to Date

      • Implemented the JwksManager class which is responsible for saving/loading/removing JSON Web Ket Sets from local storage
      • The verification part of this ticket can be done by following the example shown in this PR. This work is blocked as we need the library used (JSONWebToken) to be published. An issue has been opened for this here

      Another option was to contribute upstream to Keycloak to include the `x5c` property in the JWKS response from the JWKS endpoint but they have rejected these feature requests before. See configure keycloak to give “x5t” key in JWK response

      Attachments

        Activity

          People

            roregan Rachael O'Regan (Inactive)
            weil@redhat.com Wei Li (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: