diff --git a/oauth/client/manager.go b/oauth/client/manager.go index 7c01afa..b3b23e1 100644 --- a/oauth/client/manager.go +++ b/oauth/client/manager.go @@ -57,13 +57,19 @@ func (cm *Manager) GetClient(ctx context.Context, clientId string) (*Client, err } var jwks jwk.Key - if metadata.JWKS != nil { + if metadata.JWKS != nil && len(metadata.JWKS.Keys) > 0 { // TODO: this is kinda bad but whatever for now. there could obviously be more than one jwk, and we need to // make sure we use the right one - k, err := helpers.ParseJWKFromBytes((*metadata.JWKS)[0]) + b, err := json.Marshal(metadata.JWKS.Keys[0]) if err != nil { return nil, err } + + k, err := helpers.ParseJWKFromBytes(b) + if err != nil { + return nil, err + } + jwks = k } else if metadata.JWKSURI != nil { maybeJwks, err := cm.getClientJwks(ctx, clientId, *metadata.JWKSURI) @@ -72,6 +78,8 @@ func (cm *Manager) GetClient(ctx context.Context, clientId string) (*Client, err } jwks = maybeJwks + } else { + return nil, fmt.Errorf("no valid jwks found in oauth client metadata") } return &Client{ diff --git a/oauth/client/metadata.go b/oauth/client/metadata.go index f656ff8..6dcd720 100644 --- a/oauth/client/metadata.go +++ b/oauth/client/metadata.go @@ -1,20 +1,24 @@ package client type Metadata struct { - ClientID string `json:"client_id"` - ClientName string `json:"client_name"` - ClientURI string `json:"client_uri"` - LogoURI string `json:"logo_uri"` - TOSURI string `json:"tos_uri"` - PolicyURI string `json:"policy_uri"` - RedirectURIs []string `json:"redirect_uris"` - GrantTypes []string `json:"grant_types"` - ResponseTypes []string `json:"response_types"` - ApplicationType string `json:"application_type"` - DpopBoundAccessTokens bool `json:"dpop_bound_access_tokens"` - JWKSURI *string `json:"jwks_uri,omitempty"` - JWKS *[][]byte `json:"jwks,omitempty"` - Scope string `json:"scope"` - TokenEndpointAuthMethod string `json:"token_endpoint_auth_method"` - TokenEndpointAuthSigningAlg string `json:"token_endpoint_auth_signing_alg"` + ClientID string `json:"client_id"` + ClientName string `json:"client_name"` + ClientURI string `json:"client_uri"` + LogoURI string `json:"logo_uri"` + TOSURI string `json:"tos_uri"` + PolicyURI string `json:"policy_uri"` + RedirectURIs []string `json:"redirect_uris"` + GrantTypes []string `json:"grant_types"` + ResponseTypes []string `json:"response_types"` + ApplicationType string `json:"application_type"` + DpopBoundAccessTokens bool `json:"dpop_bound_access_tokens"` + JWKSURI *string `json:"jwks_uri,omitempty"` + JWKS *MetadataJwks `json:"jwks,omitempty"` + Scope string `json:"scope"` + TokenEndpointAuthMethod string `json:"token_endpoint_auth_method"` + TokenEndpointAuthSigningAlg string `json:"token_endpoint_auth_signing_alg"` +} + +type MetadataJwks struct { + Keys []any `json:"keys"` }