Option to check JWT Signature (#183)

This commit is contained in:
Clément Oudot 2014-11-18 14:24:03 +00:00
parent 2a33f67155
commit 27225cfe86

View File

@ -106,9 +106,11 @@ sub extractFormInfo {
$self->lmLog( "ID token: $id_token", 'debug' );
# Verify JWT signature
unless ( $self->verifyJWTSignature($id_token) ) {
$self->lmLog( "JWT signature verification failed", 'error' );
return PE_ERROR;
if ( $self->{OIDCRPCheckJWTSignature} ) {
unless ( $self->verifyJWTSignature($id_token) ) {
$self->lmLog( "JWT signature verification failed", 'error' );
return PE_ERROR;
}
}
# Get ID token content