1#ifndef SOURCEMETA_CORE_JOSE_VERIFY_H_
2#define SOURCEMETA_CORE_JOSE_VERIFY_H_
4#ifndef SOURCEMETA_CORE_JOSE_EXPORT
5#include <sourcemeta/core/jose_export.h>
9#include <sourcemeta/core/jose_algorithm.h>
10#include <sourcemeta/core/jose_jwk.h>
11#include <sourcemeta/core/jose_jwks.h>
12#include <sourcemeta/core/jose_jwt.h>
21namespace sourcemeta::core {
72 const std::chrono::seconds not_before_tolerance,
73 const std::chrono::seconds issued_at_tolerance) noexcept
102 -> std::chrono::seconds {
105 constexpr std::chrono::seconds MAXIMUM{31556952};
106 return skew < std::chrono::seconds::zero() ? std::chrono::seconds::zero()
107 : skew > MAXIMUM ? MAXIMUM
143SOURCEMETA_CORE_JOSE_EXPORT
145 const JWT &token,
const std::string_view expected_issuer,
146 const std::string_view expected_audience,
147 const std::chrono::system_clock::time_point now,
149 const std::optional<std::string_view> expected_subject = std::nullopt,
150 const std::optional<std::chrono::seconds> maximum_lifetime = std::nullopt)
151 -> std::optional<JWTClaimError>;
173SOURCEMETA_CORE_JOSE_EXPORT
175 const std::string_view signing_input,
176 const std::string_view signature,
const JWK &key)
202SOURCEMETA_CORE_JOSE_EXPORT
265SOURCEMETA_CORE_JOSE_EXPORT
267 const std::span<const JWSAlgorithm> allowed_algorithms,
268 const std::string_view expected_issuer,
269 const std::string_view expected_audience,
270 const std::chrono::system_clock::time_point now,
272 const std::optional<std::string_view> expected_subject,
273 const std::optional<std::string_view> expected_type,
274 const std::optional<std::chrono::seconds> maximum_lifetime =
275 std::nullopt) -> std::optional<JWTVerificationError>;
std::chrono::seconds issued_at
The tolerance applied to the issued-at time claim.
Definition jose_verify.h:82
JWTClockSkew(const std::chrono::seconds expiration_tolerance, const std::chrono::seconds not_before_tolerance, const std::chrono::seconds issued_at_tolerance) noexcept
Apply a distinct tolerance to each time-based claim.
Definition jose_verify.h:71
std::chrono::seconds expiration
The tolerance applied to the expiration time claim.
Definition jose_verify.h:78
std::chrono::seconds not_before
The tolerance applied to the not-before time claim.
Definition jose_verify.h:80
JWTClockSkew() noexcept=default
Apply no tolerance to any time-based claim.
SOURCEMETA_CORE_JOSE_EXPORT auto jwt_verify(const JWT &token, const JWKS &keys, const std::span< const JWSAlgorithm > allowed_algorithms, const std::string_view expected_issuer, const std::string_view expected_audience, const std::chrono::system_clock::time_point now, const JWTClockSkew clock_skew, const std::optional< std::string_view > expected_subject, const std::optional< std::string_view > expected_type, const std::optional< std::chrono::seconds > maximum_lifetime=std::nullopt) -> std::optional< JWTVerificationError >
auto jwt_bounded_clock_skew(const std::chrono::seconds skew) noexcept -> std::chrono::seconds
Definition jose_verify.h:101
JWTClaimError
Definition jose_verify.h:26
JWTVerificationError
Definition jose_verify.h:208
SOURCEMETA_CORE_JOSE_EXPORT auto jwt_check_claims(const JWT &token, const std::string_view expected_issuer, const std::string_view expected_audience, const std::chrono::system_clock::time_point now, const JWTClockSkew clock_skew={}, const std::optional< std::string_view > expected_subject=std::nullopt, const std::optional< std::chrono::seconds > maximum_lifetime=std::nullopt) -> std::optional< JWTClaimError >
SOURCEMETA_CORE_JOSE_EXPORT auto jws_verify_signature(const std::optional< JWSAlgorithm > algorithm, const std::string_view signing_input, const std::string_view signature, const JWK &key) -> bool
SOURCEMETA_CORE_JOSE_EXPORT auto jwt_verify_signature(const JWT &token, const JWK &key) -> bool
@ Lifetime
Definition jose_verify.h:41
@ Issuer
The issuer claim is missing or does not match the expected value.
Definition jose_verify.h:28
@ IssuedAt
The issued-at time claim is malformed or lies in the future.
Definition jose_verify.h:38
@ Subject
The subject claim is missing or does not match the expected value.
Definition jose_verify.h:30
@ Expiration
The expiration time claim is missing or the token has expired.
Definition jose_verify.h:34
@ NotBefore
The not-before time claim is malformed or lies in the future.
Definition jose_verify.h:36
@ Audience
The audience claim is missing or does not contain the expected value.
Definition jose_verify.h:32
@ AlgorithmNotAllowed
The token's algorithm is missing or absent from the allow-list.
Definition jose_verify.h:210
@ Signature
The named key was found but its signature did not verify.
Definition jose_verify.h:214
@ UnknownKey
No key in the set could be selected or verified the signature.
Definition jose_verify.h:212
@ Type
The token type does not match the expected media type.
Definition jose_verify.h:216