Conversation
Decrypt JWE-encrypted access tokens before writing them to the session, at both the callback and on token refresh, so req.oidc.accessToken and afterCallback always receive a plaintext JWT. Enabled by setting accessTokenDecryptionKey. The key-management algorithm is read from the JWE header and validated against a strong-algorithm allowlist; accessTokenDecryptionAlg can pin it. Decryption failures surface a clear error.
…g pin Address review feedback on JWE: - decryptAccessToken now returns non-JWE tokens (not five compact parts) unchanged instead of throwing. Toggling Token Encryption off, a mid-rollout mismatch, or an opaque-token audience no longer turns every login and refresh into a hard 500. - Constrain accessTokenDecryptionAlg to the strong-algorithm allowlist at the config layer (defense in depth), mirroring the runtime allowlist. - Add tests: an off-allowlist alg (A128KW) is rejected, non-JWE and opaque tokens pass through, and the clear-error path now uses a genuine JWE with a wrong key.
|
Addressed both majors in 95908d1:
Minor: Full suite and tsd green. |
Drop unused exportSPKI, privateJWK, privateKeyPem, fs, path bindings in the decryptAccessToken test block and an unused jar binding in the callback test.
|
Closing this PR after a scoping review. JWE access token decryption is a Resource Server concern in the HRI SDK requirements (it lives under "Resource Server Authorization", alongside mTLS token binding), not an Authentication Client / RP concern. The right home for this is the resource-server SDK ( |
Summary
Adds decryption of JWE-encrypted access tokens. When an API is configured to encrypt access tokens, the token returned at the callback is a JWE. With
accessTokenDecryptionKeyset, the SDK decrypts it before writing it to the session, soreq.oidc.accessTokenandafterCallbackalways receive a plaintext JWT with no change to consuming code.What's included
accessTokenDecryptionKey— private key for decryption. Accepts PEM string, Buffer, KeyObject, JWK, or CryptoKey. Requires a code flow (implicit flow returns no access token from the token endpoint).accessTokenDecryptionAlg— optional pin for the key-management algorithm.offline_access.afterCallbackfires, so hooks receive a usable token.accessTokenDecryptionAlg, when set, narrows the allowlist to that one value.Usage
Tests
decryptAccessToken(header auto-detect for RSA-OAEP-256/512, pin match/mismatch, non-JWE input), config validation (code-flow requirement), and end-to-end callback + refresh decryption with a clear-error case.index.test-d.ts.EXAMPLES.mdand an example atexamples/jwe.js.