drewwills / Soffit

The underside of an arch or architrave
Apache License 2.0
7 stars 7 forks source link

Proposal: Assert Identity via JWT Header #5

Closed andrewstuart closed 8 years ago

andrewstuart commented 8 years ago

I propose that we standardize on providing original user identity assertions in a signed JWT format, and that it be included only in the Authorization header as a bearer token, rather than request body.

Signatures should be generated using RSA (256+) so that they can be easily validated by consumers without exposing uPortal's private key.

Reasons I would argue for a singular location and format:

drewwills commented 8 years ago

Sounds very plausible; let's talk.

andrewstuart commented 8 years ago

Yeah, definitely. I won't be in the office for a few weeks, though (new baby tomorrow and WFH today), so I figured this would be a great place to get started. @bjagg, I think you may have comments to add here based on the mailing list discussion.

drewwills commented 8 years ago

This idea has been kicked around between Andrew, Brandon (Oakland), Aaron (Oakland), and myself. Wee all like it -- the code has been updated to work this way. Closing this ticket.