Preflight checklist
Describe the background of your feature request
We use some authentication provider like auth0, okta (you name it) to validate our developers to be able to request specific environments and services secured by heimdall in front.
Heimdall internally queries (implicit) these services and we hit rate limits on those auth providers because the jwt token did not have a kid implemented and so caches are not used.
Describe your idea
I really would love the idea of having an assertion that the kid in the jwt must be present for the auth provider to be queried.
That would explicitly fail if kid is not there and would allow to use cached results for kid's.
Are there any workarounds or alternatives?
Yeah there are other options.
- of course make sure all code implements a kid but if it is forgotten we hit rate limits and all apis go down
- implement another level of cache in between heimdall and auth provider (caching is hard...)
Version
0.17.9
Additional Context
No response
Preflight checklist
Describe the background of your feature request
We use some authentication provider like auth0, okta (you name it) to validate our developers to be able to request specific environments and services secured by heimdall in front.
Heimdall internally queries (implicit) these services and we hit rate limits on those auth providers because the jwt token did not have a kid implemented and so caches are not used.
Describe your idea
I really would love the idea of having an assertion that the kid in the jwt must be present for the auth provider to be queried.
That would explicitly fail if kid is not there and would allow to use cached results for kid's.
Are there any workarounds or alternatives?
Yeah there are other options.
Version
0.17.9
Additional Context
No response