Browse Source

put 'kid' into JWS header, closes #784

pull/873/head
Justin Richer 10 years ago
parent
commit
22c86d09f8
  1. 8
      openid-connect-server/src/main/java/org/mitre/openid/connect/service/impl/DefaultOIDCTokenService.java

8
openid-connect-server/src/main/java/org/mitre/openid/connect/service/impl/DefaultOIDCTokenService.java

@ -178,10 +178,14 @@ public class DefaultOIDCTokenService implements OIDCTokenService {
// sign it with the client's secret // sign it with the client's secret
signer.signJwt((SignedJWT) idToken); signer.signJwt((SignedJWT) idToken);
} else { } else {
idClaims.setCustomClaim("kid", jwtService.getDefaultSignerKeyId()); idClaims.setCustomClaim("kid", jwtService.getDefaultSignerKeyId());
JWSHeader header = new JWSHeader(signingAlg);
header.setKeyID(jwtService.getDefaultSignerKeyId());
idToken = new SignedJWT(new JWSHeader(signingAlg), idClaims); idToken = new SignedJWT(header, idClaims);
// sign it with the server's key // sign it with the server's key
jwtService.signJwt((SignedJWT) idToken); jwtService.signJwt((SignedJWT) idToken);
} }

Loading…
Cancel
Save