Skip to content

localjwtauthority: sign actor JWTs with go-jose #2203

Description

localjwtauthority.sign builds actor JWTs by hand. It base64url-encodes the header and claims, hashes the signing input, and formats each signature itself, including the fixed-width r || s encoding that ES256 requires. go-jose has been a direct dependency since #1961 and does all of this through jose.NewSigner and jwt.Signed, so we could drop our own encoding and signature code.

This came up in review of #1961: #1961 (comment)

Change

  • Replace sign with a go-jose signer built from the authority's key and algorithm, setting typ: JWT and kid as protected headers.
  • Keep the payload as the existing actoridjwt wire claims, so the claims tokens carry don't change.
  • Keep every algorithm sign accepts today: RS256, RS384, RS512, and ES256 with a P-256 key.

Tests

  • A token signed with each supported algorithm verifies against the authority's public key.
  • The header carries alg, kid, and typ: JWT, which TestSignJWTHeader checks today.
  • An unsupported algorithm, and an ES256 authority whose key isn't P-256, both return an error.

The order and spacing of the header's JSON may change. Verifiers parse the header, so nothing should depend on its exact bytes.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area/identitykind/cleanupSmall fixes that are not bugs, for example a typo in a code comment

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions