Skip to content

feat(identity-jwt): support typed credential locations #64

Description

@araujof

Description

The JWT identity plugin reads one configured HTTP header. Add a typed credential location that can read a JWT from a header, cookie, or query parameter. Keep one location per resolver so precedence and fallback remain out of scope.

Header-based configuration must remain backward compatible. Query extraction must use a request target supplied explicitly by the host; it must not depend on whether HttpExtension.path happens to include a query string. Missing, empty, duplicated, or malformed credentials must deny with a location-specific error, without logging the credential.

Acceptance criteria

  • JWT configuration accepts header, cookie, and query credential locations.
  • The existing header: setting continues to work and has a documented migration path to the typed form.
  • The identity input carries enough request information to parse query parameters consistently across hosts.
  • Cookie and query parsing handle encoding and duplicate names deterministically; ambiguous input is rejected.
  • The resolved raw credential records its origin without storing the credential in diagnostics, Debug, or tracing output.
  • Missing or malformed credentials fail closed with tests for every location.
  • Existing header-based JWT tests remain green.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions