Uploaded image for project: 'OpenId Connect'
  1. OpenId Connect
  2. OIDC-317

Cache the JWKSet used to verify signatures

    XMLWordPrintable

Details

    • Improvement
    • Resolution: Unresolved
    • Major
    • None
    • 2.25.4
    • Authenticator
    • Unknown

    Description

      Currently, when verifying a signature (like the id token signature), a new HTTP request is executed to download the JWKSet.

      It should ideally be cached (and refreshed regularly to avoid being out of date).

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              tmortagne Thomas Mortagne
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

              Dates

                Created:
                Updated: