-
Notifications
You must be signed in to change notification settings - Fork 432
Description
Today:
EdDSA signed JWTs
Future:
The goal is for this list: https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/blob/dev/src/System.IdentityModel.Tokens.Jwt/JwtSecurityTokenHandler.cs#L62 to support an EdDSA signature strategy so that dependencies of this library understand how to handle EdDSA signed JWTs.
In this case the issue is sourced from Microsoft.AspNetCore.Authorization.Authorize attribute which attempts to use System.IdentityModel.Tokens.Jwt through the package Microsoft.AspNetCore.Authentication.JwtBearer (this repo) package for verifying the incoming tokens.
Related:
- [Bug] IDX10503: Signature validation failed. Token does not have a kid. (System.NotImplementedException: The method or operation is not implemented. at Microsoft.IdentityModel.Tokens.SignatureProvider.Verify...) #1970
- How to get the user claim populated so that standard attributes can be used Authress/authress-sdk.cs#20
If a PR is opened to add this support, will it be accepted and helped to be shepherded to completion or will a PR of this nature lay on apathetic ears?