|
ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
|
OpenID Connect ID Token validation, RS256 (PROTOCORE_ENABLE_OIDC). More...
#include "protocore_config.h"Go to the source code of this file.
OpenID Connect ID Token validation, RS256 (PROTOCORE_ENABLE_OIDC).
The Relying Party side of OpenID Connect Core 1.0 sec 3.1.3.7 "ID Token Validation". That document is an OpenID Foundation specification, not an IETF RFC; the token it carries is an IETF one, a JWS in the Compact Serialization (RFC 7515 sec 7.1) whose alg is RS256, which JWA (RFC 7518 sec 3.3) defines as RSASSA-PKCS1-v1_5 using SHA-256 over the JWS Signing Input (RFC 7515 sec 2). Given an ID Token and the OP's JWK Set (RFC 7517 sec 5), a verify:
alg == RS256 (RFC 7515 sec 4.1.1; OIDC Core sec 3.1.3.7 step 7 makes RS256 the default),kid (RFC 7515 sec 4.1.4), or the sole RSA key when the JOSE Header carries no kid,iss (step 2, RFC 7519 sec 4.1.1) and aud in both its string and array forms (step 3, RFC 7519 sec 4.1.3), and reads exp (step 9, RFC 7519 sec 4.1.4) and nbf (RFC 7519 sec 4.1.5) against the caller's clock,sub (RFC 7519 sec 4.1.2), email (OIDC Core sec 5.1) and the times in ::protocore_oidc_claims.Zero heap: the decode buffers come from the per-dispatch arena and everything else is fixed. The verifier fetches nothing. Retrieving the JWK Set from the OP's jwks_uri (OpenID Connect Discovery 1.0 sec 3) over HTTPS and caching it belongs to the caller, which leaves key rotation and TLS trust in the application's hands and this module deterministic.
Only RS256 is verified. A MAC-based alg (OIDC Core sec 3.1.3.7 step 8) is the JWT module's (services/security/jwt); ES256 is out of scope.
The module exports one symbol, Oidc. Everything in oidc.c has internal linkage.
Definition in file oidc.h.