Replies: 1 comment 3 replies
-
|
Thanks for the feedback @enzomotta They are supposed to be cached. See the logic here: https://github.com/micronaut-projects/micronaut-security/blob/master/security-jwt/src/main/java/io/micronaut/security/token/jwt/signature/jwks/JwksSignature.java |
Beta Was this translation helpful? Give feedback.
3 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Hi there,
I was using only AWS Cognito to authenticate my users and everything was perfect til I had to support Google and Apple native logins. So, to validate those jwts so I added the respective JWKS on my application.yml and I'm validating issuer and audience on a custom JwtAuthenticationFactory implementation. After that I notice that every request I received had Micronaut downloading the JWKS jsons from Google and Apple. Wasn't it supposed to cache those calls? It appears to me that the cognito JWKS is been cached cause its not been downloaded all the time.
My application.yml looks something like this:
Am I missing something?
Thanks in advance,
Enzo.
Beta Was this translation helpful? Give feedback.
All reactions