Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add httpsig to RS token introspection requests #576

Closed
wilsonianb opened this issue Aug 29, 2022 · 2 comments
Closed

Add httpsig to RS token introspection requests #576

wilsonianb opened this issue Aug 29, 2022 · 2 comments
Labels
pkg: backend Changes in the backend package.

Comments

@wilsonianb wilsonianb added the pkg: backend Changes in the backend package. label Aug 29, 2022
@wilsonianb
Copy link
Contributor Author

Since we're assuming the RS and AS are operated by the same account provider, we can make token introspection http signature validation optional. The AS won't publicly expose that endpoint.

@matdehaast
Copy link
Collaborator

Closing for now due to AS-RS being in a trusted zone

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
pkg: backend Changes in the backend package.
Projects
No open projects
Status: Done
Development

No branches or pull requests

3 participants