italia / spid-cie-oidc-django

The SPID/CIE OIDC Federation SDK, written in Python
Apache License 2.0
27 stars 28 forks source link

[Provider] private_key_jwt replay #241

Open peppelinux opened 2 years ago

peppelinux commented 2 years ago

Following the work made in release https://github.com/italia/spid-cie-oidc-django/releases/tag/v0.8.2

we have to consider that we don't have any mechanisms to check if a private_key_jwt is replied. I think that we should do something in this side to improve the security, the lookup parameter would be jti