feat(oauth): add acr and auth_time to JWT access token and introspect - #20980
Open
StaberindeZA wants to merge 3 commits into
Open
feat(oauth): add acr and auth_time to JWT access token and introspect#20980StaberindeZA wants to merge 3 commits into
StaberindeZA wants to merge 3 commits into
Conversation
Because:
* RFC 9470 section 5 requires the authorization server to include acr
and auth_time on the access token, but the JWT access token builder
emitted neither
* the ID token already carries both; the access token should match
This commit:
* emits acr ("AAL" + aal) and auth_time on the JWT access token,
mirroring the ID token, whenever the grant carries aal/authAt
* sources auth_time from grant.authAt directly, which is already in
seconds (matching the token response auth_at) — no extra conversion
* adds unit tests for the new claims
Closes #FXA-14309
Because:
* RFC 9470 section 6.2 adds acr and auth_time as top-level introspection
members, but these values were unreachable — they lived only on the
codes row, which is deleted at token exchange and never copied onto
the access token
This commit:
* persists authAt, amr, and aal on the Redis-backed access token
(model constructor, toJSON, and parse; threaded through
AccessToken.generate and generateAccessToken from the grant)
* returns acr ("AAL" + aal), auth_time (seconds, from authAt), and amr
from /introspect for access tokens, and adds them to the Joi schema
* leaves refresh tokens untouched, so elevation does not survive a
token refresh
* adds unit tests for the model round-trip and field threading, plus
introspection assertions in the remote suite
Closes #FXA-14310
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Because
This pull request
Issue that this pull request solves
Closes: FXA-14309 / FXA-14310
Checklist
Put an
xin the boxes that applyHow to review (Optional)
Screenshots (Optional)
Please attach the screenshots of the changes made in case of change in user interface.
Other information (Optional)
Any other information that is important to this pull request.