misc: improve support for jwks via http

This commit is contained in:
Sheen Capadngan
2025-03-12 00:41:05 +08:00
parent 872a3fe48d
commit 4dc56033b1
@@ -78,14 +78,22 @@ export const identityJwtAuthServiceFactory = ({
let tokenData: Record<string, string | boolean | number> = {}; let tokenData: Record<string, string | boolean | number> = {};
if (identityJwtAuth.configurationType === JwtConfigurationType.JWKS) { if (identityJwtAuth.configurationType === JwtConfigurationType.JWKS) {
const decryptedJwksCaCert = orgDataKeyDecryptor({ let client: JwksClient;
cipherTextBlob: identityJwtAuth.encryptedJwksCaCert if (identityJwtAuth.jwksUrl.includes("https:")) {
}).toString(); const decryptedJwksCaCert = orgDataKeyDecryptor({
const requestAgent = new https.Agent({ ca: decryptedJwksCaCert, rejectUnauthorized: !!decryptedJwksCaCert }); cipherTextBlob: identityJwtAuth.encryptedJwksCaCert
const client = new JwksClient({ }).toString();
jwksUri: identityJwtAuth.jwksUrl,
requestAgent const requestAgent = new https.Agent({ ca: decryptedJwksCaCert, rejectUnauthorized: !!decryptedJwksCaCert });
}); client = new JwksClient({
jwksUri: identityJwtAuth.jwksUrl,
requestAgent
});
} else {
client = new JwksClient({
jwksUri: identityJwtAuth.jwksUrl
});
}
const { kid } = decodedToken.header; const { kid } = decodedToken.header;
const jwtSigningKey = await client.getSigningKey(kid); const jwtSigningKey = await client.getSigningKey(kid);