|
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 33s
Completes KEY-WP-0019. Client.Verify now delegates JWK-set parsing and RS256 signature checking to internal/jose, so the caller path and upstream provider verification share one implementation rather than two copies that drift. Its claim policy stays put: audience and nonce bindings belong to the caller. The existing authclient tests pass unchanged, which is the evidence the migration preserved behaviour. One deliberate strictness increase: a key set containing any malformed RSA signing key is refused outright rather than used alongside a good key. KeyCape's /jwks publishes a single key, so no current deployment is affected. Adds direct tests for internal/jose. It is now the single verifier behind both paths, and testing it only through its callers would leave duplicate key ids, crit headers, even exponents and undersized moduli covered by accident. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NV9oijZukGyGbRQGGKnK4P Assistant: claude-code Assistant-Model: opus Assistant-Process: 713576@bnt-lap001 Assistant-Session: 384c511d-9bce-4cb8-a676-2aef6c0c8df6 |
||
|---|---|---|
| .. | ||
| jose.go | ||
| jose_test.go | ||