Skip to content

fix: accept string audiences in ID tokens - #58

Open
Shubham-Padkonde wants to merge 1 commit into
intuit:masterfrom
Shubham-Padkonde:fix/string-id-token-audience
Open

Shubham-Padkonde wants to merge 1 commit into
intuit:masterfrom
Shubham-Padkonde:fix/string-id-token-audience

Conversation

@Shubham-Padkonde

Copy link
Copy Markdown

validate_id_token rejects valid ID tokens with a string-valued audience because it compares the first character of aud with the client ID. OpenID Connect allows a single audience to be represented as a string (section 2).

Normalize a string audience to a one-element list before the existing comparison. Signature verification, issuer/expiry checks, and existing array handling remain in place.

The new tests use real RS256 signatures and cover matching string/list audiences, mismatched audiences, a string with a matching prefix, and an invalid signature. The matching-string case fails before the fix. All 30 tests pass afterward, including the existing discovery tests; git diff --check passes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant