← Back to plugin index

JWKS Ticket Verifier Settings

Description

JWT Signature verification based on fetching key information from a URL providing a JWKS (see RFC7517).

Type name
JwksSignatureVerifierSettings
Class
com.airlock.iam.common.application.configuration.jwt.signature.JwksSignatureVerifierSettings
May be used by
Properties
JWKS URL (url)
Description

The URL providing the JWKS. Must be an absolute URL with "https" scheme.

Attributes
String
Mandatory
HTTP Client (httpClient)
Description

The HTTP Client used to fetch the JWKS data

Attributes
Plugin-Link
Mandatory
Assignable plugins
Cache Refresh Time [minutes] (cacheRefreshTimeInMinutes)
Description
Time in minutes after which cached data from the JWKS endpoint is refreshed.

The refresh is asynchronous: the first request after this time still receives the previously cached data and triggers a reload in the background.

Subsequent requests receive the refreshed data.

Data not requested for twice this time expires and is reloaded synchronously on the next request, so served data is never older than twice this time.

The JWKS data is additionally reloaded if a key is not yet known, or if a signature check with a known key fails.

If a refresh fails, the previously fetched data is kept while the entry is still in use.

Attributes
Integer
Optional
Default value
10
YAML Template (with default values)

type: JwksSignatureVerifierSettings
id: JwksSignatureVerifierSettings-xxxxxx
displayName: 
comment: 
properties:
  cacheRefreshTimeInMinutes: 10
  httpClient:
  url: