Sourcemeta Core 0.0.0
Loading...
Searching...
No Matches
jose_verify.h
1#ifndef SOURCEMETA_CORE_JOSE_VERIFY_H_
2#define SOURCEMETA_CORE_JOSE_VERIFY_H_
3
4#ifndef SOURCEMETA_CORE_JOSE_EXPORT
5#include <sourcemeta/core/jose_export.h>
6#endif
7
8// NOLINTBEGIN(misc-include-cleaner)
9#include <sourcemeta/core/jose_algorithm.h>
10#include <sourcemeta/core/jose_jwk.h>
11#include <sourcemeta/core/jose_jwks.h>
12#include <sourcemeta/core/jose_jwt.h>
13// NOLINTEND(misc-include-cleaner)
14
15#include <chrono> // std::chrono::seconds, std::chrono::system_clock
16#include <cstdint> // std::uint8_t
17#include <optional> // std::optional
18#include <span> // std::span
19#include <string_view> // std::string_view
20
21namespace sourcemeta::core {
22
43
62 JWTClockSkew() noexcept = default;
63
64 // The conversion is deliberately implicit so that a caller holding a single
65 // uniform tolerance can keep passing plain seconds
67 JWTClockSkew(const std::chrono::seconds uniform) noexcept
68 : expiration{uniform}, not_before{uniform}, issued_at{uniform} {}
69
71 JWTClockSkew(const std::chrono::seconds expiration_tolerance,
72 const std::chrono::seconds not_before_tolerance,
73 const std::chrono::seconds issued_at_tolerance) noexcept
74 : expiration{expiration_tolerance}, not_before{not_before_tolerance},
75 issued_at{issued_at_tolerance} {}
76
78 std::chrono::seconds expiration{0};
80 std::chrono::seconds not_before{0};
82 std::chrono::seconds issued_at{0};
83};
84
101inline auto jwt_bounded_clock_skew(const std::chrono::seconds skew) noexcept
102 -> std::chrono::seconds {
103 // A mean Gregorian year, the widest grace period any deployment plausibly
104 // needs, so an extreme value cannot widen the acceptance window without bound
105 constexpr std::chrono::seconds MAXIMUM{31556952};
106 return skew < std::chrono::seconds::zero() ? std::chrono::seconds::zero()
107 : skew > MAXIMUM ? MAXIMUM
108 : skew;
109}
110
143SOURCEMETA_CORE_JOSE_EXPORT
145 const JWT &token, const std::string_view expected_issuer,
146 const std::string_view expected_audience,
147 const std::chrono::system_clock::time_point now,
148 const JWTClockSkew clock_skew = {},
149 const std::optional<std::string_view> expected_subject = std::nullopt,
150 const std::optional<std::chrono::seconds> maximum_lifetime = std::nullopt)
151 -> std::optional<JWTClaimError>;
152
173SOURCEMETA_CORE_JOSE_EXPORT
174auto jws_verify_signature(const std::optional<JWSAlgorithm> algorithm,
175 const std::string_view signing_input,
176 const std::string_view signature, const JWK &key)
177 -> bool;
178
202SOURCEMETA_CORE_JOSE_EXPORT
203auto jwt_verify_signature(const JWT &token, const JWK &key) -> bool;
204
233
265SOURCEMETA_CORE_JOSE_EXPORT
266auto jwt_verify(const JWT &token, const JWKS &keys,
267 const std::span<const JWSAlgorithm> allowed_algorithms,
268 const std::string_view expected_issuer,
269 const std::string_view expected_audience,
270 const std::chrono::system_clock::time_point now,
271 const JWTClockSkew clock_skew,
272 const std::optional<std::string_view> expected_subject,
273 const std::optional<std::string_view> expected_type,
274 const std::optional<std::chrono::seconds> maximum_lifetime =
275 std::nullopt) -> std::optional<JWTVerificationError>;
276
277} // namespace sourcemeta::core
278
279#endif
std::chrono::seconds issued_at
The tolerance applied to the issued-at time claim.
Definition jose_verify.h:82
JWTClockSkew(const std::chrono::seconds expiration_tolerance, const std::chrono::seconds not_before_tolerance, const std::chrono::seconds issued_at_tolerance) noexcept
Apply a distinct tolerance to each time-based claim.
Definition jose_verify.h:71
std::chrono::seconds expiration
The tolerance applied to the expiration time claim.
Definition jose_verify.h:78
std::chrono::seconds not_before
The tolerance applied to the not-before time claim.
Definition jose_verify.h:80
JWTClockSkew() noexcept=default
Apply no tolerance to any time-based claim.
Definition jose_jwk.h:40
Definition jose_jwks.h:40
Definition jose_jwt.h:38
SOURCEMETA_CORE_JOSE_EXPORT auto jwt_verify(const JWT &token, const JWKS &keys, const std::span< const JWSAlgorithm > allowed_algorithms, const std::string_view expected_issuer, const std::string_view expected_audience, const std::chrono::system_clock::time_point now, const JWTClockSkew clock_skew, const std::optional< std::string_view > expected_subject, const std::optional< std::string_view > expected_type, const std::optional< std::chrono::seconds > maximum_lifetime=std::nullopt) -> std::optional< JWTVerificationError >
auto jwt_bounded_clock_skew(const std::chrono::seconds skew) noexcept -> std::chrono::seconds
Definition jose_verify.h:101
JWTClaimError
Definition jose_verify.h:26
JWTVerificationError
Definition jose_verify.h:208
SOURCEMETA_CORE_JOSE_EXPORT auto jwt_check_claims(const JWT &token, const std::string_view expected_issuer, const std::string_view expected_audience, const std::chrono::system_clock::time_point now, const JWTClockSkew clock_skew={}, const std::optional< std::string_view > expected_subject=std::nullopt, const std::optional< std::chrono::seconds > maximum_lifetime=std::nullopt) -> std::optional< JWTClaimError >
SOURCEMETA_CORE_JOSE_EXPORT auto jws_verify_signature(const std::optional< JWSAlgorithm > algorithm, const std::string_view signing_input, const std::string_view signature, const JWK &key) -> bool
SOURCEMETA_CORE_JOSE_EXPORT auto jwt_verify_signature(const JWT &token, const JWK &key) -> bool
@ Lifetime
Definition jose_verify.h:41
@ Issuer
The issuer claim is missing or does not match the expected value.
Definition jose_verify.h:28
@ IssuedAt
The issued-at time claim is malformed or lies in the future.
Definition jose_verify.h:38
@ Subject
The subject claim is missing or does not match the expected value.
Definition jose_verify.h:30
@ Expiration
The expiration time claim is missing or the token has expired.
Definition jose_verify.h:34
@ NotBefore
The not-before time claim is malformed or lies in the future.
Definition jose_verify.h:36
@ Audience
The audience claim is missing or does not contain the expected value.
Definition jose_verify.h:32
@ AlgorithmNotAllowed
The token's algorithm is missing or absent from the allow-list.
Definition jose_verify.h:210
@ Signature
The named key was found but its signature did not verify.
Definition jose_verify.h:214
@ UnknownKey
No key in the set could be selected or verified the signature.
Definition jose_verify.h:212
@ Type
The token type does not match the expected media type.
Definition jose_verify.h:216
Definition jose_verify.h:60