fix: skew of 30 seconds for JWT validation
This commit is contained in:
committed by
Steve Chavez
parent
887948d259
commit
c10ba8e214
@@ -9,6 +9,8 @@ This project adheres to [Semantic Versioning](http://semver.org/).
|
|||||||
|
|
||||||
- #2762, Fixes "permission denied for schema" error during schema cache load - @steve-chavez
|
- #2762, Fixes "permission denied for schema" error during schema cache load - @steve-chavez
|
||||||
- #2756, Fix bad error message on generated columns when using `Prefer: missing=default` - @steve-chavez
|
- #2756, Fix bad error message on generated columns when using `Prefer: missing=default` - @steve-chavez
|
||||||
|
- #1139, Allow a 30 second skew for JWT validation - @steve-chavez
|
||||||
|
+ It used to be 1 second, which was too strict
|
||||||
|
|
||||||
## [11.0.0] - 2023-04-16
|
## [11.0.0] - 2023-04-16
|
||||||
|
|
||||||
|
|||||||
@@ -63,7 +63,7 @@ parseToken AppConfig{..} token time = do
|
|||||||
liftEither . mapLeft jwtClaimsError $ JSON.toJSON <$> eitherClaims
|
liftEither . mapLeft jwtClaimsError $ JSON.toJSON <$> eitherClaims
|
||||||
where
|
where
|
||||||
validation =
|
validation =
|
||||||
JWT.defaultJWTValidationSettings audienceCheck & set JWT.allowedSkew 1
|
JWT.defaultJWTValidationSettings audienceCheck & set JWT.allowedSkew 30
|
||||||
|
|
||||||
audienceCheck :: JWT.StringOrURI -> Bool
|
audienceCheck :: JWT.StringOrURI -> Bool
|
||||||
audienceCheck = maybe (const True) (==) configJwtAudience
|
audienceCheck = maybe (const True) (==) configJwtAudience
|
||||||
|
|||||||
Reference in New Issue
Block a user