oxctl / spring-security-lti13

A LTI 1.3 implementation for Spring Security that builds on the OAuth2 support
Apache License 2.0
14 stars 7 forks source link

Cache on jwkSetUri not clientId #35

Closed buckett closed 1 year ago

buckett commented 1 year ago

At the moment if we change the jwkSetUri on a client registration it continues to use the old value because we cache the validator based on the client ID. This isn't a problem if config changes require an application restart, but if the value can be changed at runtime it doesn't get picked up because the old validator is still in the cache.