Files
oauth2-proxy/providers
andoksandJan Larwig 7c96234233 feat: add support for specifying allowed OIDC JWT signing algorithms (#2753) (#2851)
* feat: add support for specifying allowed OIDC JWT signing algorithms (#2753)

TODO:
- [X] update docs
- [X] add support in yaml (modern) config
- [X] add more test(s)?

Add (legacy for now) configuration flag "oidc-enabled-signing-alg" (cfg:
oidc_enabled_signing_algs) that allows setting what signing algorithms
are specified by provider in JWT header ("alg" header claim).

In particular useful when skip_oidc_discovery = true, as verifier
defaults to only accept "RS256" in alg field in such circumstances.

Signed-off-by: Jan Larwig <jan@larwig.com>

* doc: update changelog and alpha config

Signed-off-by: Jan Larwig <jan@larwig.com>

* feat: add signing algorithm intersection handling with oidc discovery and additional tests

Signed-off-by: Jan Larwig <jan@larwig.com>

---------

Signed-off-by: Jan Larwig <jan@larwig.com>
Co-authored-by: Jan Larwig <jan@larwig.com>
2026-03-18 22:24:27 +08:00
..
2025-11-16 22:38:59 +01:00
2024-03-04 01:42:00 +01:00
2025-08-12 17:41:45 +02:00
2022-10-21 11:57:51 +01:00
2025-08-19 08:40:36 +02:00
2024-01-22 13:39:53 +00:00
2024-01-22 13:39:53 +00:00
2022-10-21 11:57:51 +01:00
2024-03-04 01:42:00 +01:00
2024-01-22 13:39:53 +00:00