Skip to content

allow assertion to check for kid to be present #3056

Description

@julianhille

Preflight checklist

Describe the background of your feature request

We use some authentication provider like auth0, okta (you name it) to validate our developers to be able to request specific environments and services secured by heimdall in front.

Heimdall internally queries (implicit) these services and we hit rate limits on those auth providers because the jwt token did not have a kid implemented and so caches are not used.

Describe your idea

I really would love the idea of having an assertion that the kid in the jwt must be present for the auth provider to be queried.
That would explicitly fail if kid is not there and would allow to use cached results for kid's.

Are there any workarounds or alternatives?

Yeah there are other options.

  • of course make sure all code implements a kid but if it is forgotten we hit rate limits and all apis go down
  • implement another level of cache in between heimdall and auth provider (caching is hard...)

Version

0.17.9

Additional Context

No response

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    featureUsed for new features

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions