Description
The JWT identity plugin reads one configured HTTP header. Add a typed credential location that can read a JWT from a header, cookie, or query parameter. Keep one location per resolver so precedence and fallback remain out of scope.
Header-based configuration must remain backward compatible. Query extraction must use a request target supplied explicitly by the host; it must not depend on whether HttpExtension.path happens to include a query string. Missing, empty, duplicated, or malformed credentials must deny with a location-specific error, without logging the credential.
Acceptance criteria
- JWT configuration accepts header, cookie, and query credential locations.
- The existing
header: setting continues to work and has a documented migration path to the typed form.
- The identity input carries enough request information to parse query parameters consistently across hosts.
- Cookie and query parsing handle encoding and duplicate names deterministically; ambiguous input is rejected.
- The resolved raw credential records its origin without storing the credential in diagnostics,
Debug, or tracing output.
- Missing or malformed credentials fail closed with tests for every location.
- Existing header-based JWT tests remain green.
Description
The JWT identity plugin reads one configured HTTP header. Add a typed credential location that can read a JWT from a header, cookie, or query parameter. Keep one location per resolver so precedence and fallback remain out of scope.
Header-based configuration must remain backward compatible. Query extraction must use a request target supplied explicitly by the host; it must not depend on whether
HttpExtension.pathhappens to include a query string. Missing, empty, duplicated, or malformed credentials must deny with a location-specific error, without logging the credential.Acceptance criteria
header:setting continues to work and has a documented migration path to the typed form.Debug, or tracing output.