Repository navigation
feat: Add optional issuers check to session authentication - #433
Conversation
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
🤖 Devin AI EngineerI'll be helping with this pull request! Here's what you should know: ✅ I will automatically:
Note: I can only respond to comments from users who have write access to this repository. ⚙️ Control Options:
Original prompt from madison.packer
|
|
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
|
Doc follow-ups from review — all LOW/INFO, not blockers. 1. Expand the * The match is exact (case-sensitive). The `iss` value WorkOS mints varies
* by environment — `https://api.workos.com`,
* `https://api.workos.com/user_management/<clientId>`, or a custom auth
* domain — so pass the precise value(s) your tokens actually carry.2. Mirror 3. Note on |
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
|
All three addressed in 34de9a0:
Doc-only change; |
gjtorikian
left a comment
There was a problem hiding this comment.
LGTM. Verified independently:
- Issuer logic is sound: opt-in (null = unchanged), fail-closed on empty list, exact case-sensitive match per RFC 7519 (matches
jose.jwtVerifyin workos/node#1694). - Binary compat preserved:
javapconfirms all 3 baseSessionCookieconstructors retained, additions are additive. - Tests: 18 pass, 0 failures — covers null/match/mismatch/absent/multi/empty issuer cases.
- Doc follow-ups from review all addressed in 34de9a0 (exact-match semantics, environment variance,
refresh()non-enforcement,@param issuersmirrored ontoauthenticateWithSessionCookie). - All 7 CI checks green.
Summary
Lets apps opt in to validating the
issclaim of session access tokens. Part of the cross-SDK rollout started in workos/authkit-react-router#83 (see also workos/workos-node#1694, workos/workos-python#725, workos/workos-ruby#552, workos/workos-php#440). Default behavior is unchanged: with no issuers passed,issis not checked, exactly as before.WorkOS's constructor lives in generatedWorkOS.kt(oagen), so the option is a per-call parameter on the hand-maintained session helpers rather than client config:Jwks.isValidJwtkeeps its existing NimbusDefaultJWTProcessor(signature + defaultexp/nbfchecks) and, whenissuers != null, additionally requiresclaims.issuerto be non-null and contained in the list. An explicit empty list fails closed (rejects every token). Mismatches surface as the existingAuthenticateSessionFailureReason.INVALID_JWT.refresh()does not verify a JWT and is unchanged.SessionCookiesnapshots the list (issuers?.toList()) so caller mutation can't change the policy later.Binary compatibility: the old
SessionCookieJVM constructors —(UM, String, String),(UM, String, String, ObjectMapper)and the synthetic$defaultone — are unchanged (verified withjavap);loadSealedSession/authenticateWithSessionCookiegain@JvmOverloadsso their two-arg descriptors also remain.Tests:
./script/ci(ktlint, full test suite, Dokka) passes. NewSessionTestcases cover unset, matching, mismatched, absentiss, list, and empty list.Link to Devin session: https://app.devin.ai/sessions/0ee38e859a9849658a7cdb2d215d89a6
Open in Devin Desktop: https://app.devin.ai/desktop/session/0ee38e859a9849658a7cdb2d215d89a6?variant=devin
Requested by: @m0tzy