Validate issuer

This commit is contained in:
Sebastian H. Gabrielli 2023-12-30 13:51:38 +01:00
parent 3a548ad1c7
commit 08d7983f5b

View File

@ -7,12 +7,16 @@ struct MyClaims {
sub: String,
exp: usize,
aud: String,
iss: String,
preferred_username: Option<String>
}
fn validate_jwt(token: &str, public_key_pem: String) -> Result<MyClaims> {
let mut validation = Validation::new(Algorithm::RS256);
validation.set_audience(&["CLaLr8sikEiN7NCrPMhjhbtLZgnZJ6JZVzPdVN5P"]);
validation.set_issuer(&["https://sso.gitgals.com/application/o/sebtest/"]);
let token_data = decode::<MyClaims>(
token,
@ -24,7 +28,8 @@ fn validate_jwt(token: &str, public_key_pem: String) -> Result<MyClaims> {
}
fn main() {
let token = "eyJhbGciOiJSUzI1NiIsImtpZCI6IjExOTMxYjliMjVhZjJmNjYyZjQ4NjNkYjAwZTJhMjg5IiwidHlwIjoiSldUIn0.eyJpc3MiOiJodHRwczovL3Nzby5naXRnYWxzLmNvbS9hcHBsaWNhdGlvbi9vL3NlYnRlc3QvIiwic3ViIjoiZjJiNzIwOGY2MTcwYWI0NWNlZGM1OGUzMTM0NGNjNGY3MGQzZWRjMjhkYWZkMmJlNDZkNzIxMzM1ZDQxZDk2NCIsImF1ZCI6IkNMYUxyOHNpa0VpTjdOQ3JQTWhqaGJ0TFpnblpKNkpaVnpQZFZONVAiLCJleHAiOjE3MDM5Mzk5ODEsImlhdCI6MTcwMzkzOTg2MSwiYXV0aF90aW1lIjoxNzAzODU3NzMwLCJhY3IiOiJnb2F1dGhlbnRpay5pby9wcm92aWRlcnMvb2F1dGgyL2RlZmF1bHQiLCJlbWFpbCI6IiIsImVtYWlsX3ZlcmlmaWVkIjp0cnVlLCJuYW1lIjoiSW5zb21uaWEiLCJnaXZlbl9uYW1lIjoiSW5zb21uaWEiLCJwcmVmZXJyZWRfdXNlcm5hbWUiOiJpbnNvbW5pYS10ZXN0Iiwibmlja25hbWUiOiJpbnNvbW5pYS10ZXN0IiwiZ3JvdXBzIjpbXSwiYXpwIjoiQ0xhTHI4c2lrRWlON05DclBNaGpoYnRMWmduWko2SlpWelBkVk41UCIsInVpZCI6IkRtSjNDbW5UZXFRYlhhR0RYVmFsNkdYRExtb2o0QzZ6QXZNaFNZOEoifQ.nKbZgz9xYuZJhWxSaKjn8tXadehy2vl6ldvYPzvOC0iT150qj6Y0H06QH7JqNsf0t8InPS7wJVGqD5Np0x8xIOQzUSRPI3dpel8ISdJIUGtKafmzqlUYiBRqaFqTpdSdsgpQ0y45I2tedV2jb9W-yGuv2uVE5tGAvXRIIbHzPBmkvdt_Sm6exYRCUgV2IXKYB_YWT2sCFmGHl-_4Fr8iRgmAijsbjPhW-sPreGQztG6F-odGuaLFD09g10X3PtP_iaIgFUg6ycZ_vGbSos9ITwmeh3Ff4NpLXi_HUNuePx912pADfNzB375dmV6tZpYeVFwxpBeJ3J7_egEVlqxq-4YK7LoDCOx7WnHAGmP8s8V-oCVkWecXTVEdenujQ3A3KlCxgu8Hs7AnreIhllDRA5eEGYusc67JqylatfdcE6Ug8rT2Kgoc6xuYZyyWP7r61xj-Dfy9EBpTvrVF1UuzwcEzT8-ml6jjtoG_VQPlj_df3L_bXudjBnO7d3382R4PBGcZBSoiDmGGSyly2U0fBdWMtd0oqBHyjFBumot_ZBoQ-N5oDaxyoHYd3_auY5coPHusM5KvfKmftRUWAcrF2X4cJPZpG87-K1Nnf4XghLAl6zFytoRvWH-QYdOuwwHNGwXOIXA_9RjHmIytANv1JZBpksrIn2VcWrdMujG1MGE";
let token = "eyJhbGciOiJSUzI1NiIsImtpZCI6IjExOTMxYjliMjVhZjJmNjYyZjQ4NjNkYjAwZTJhMjg5IiwidHlwIjoiSldUIn0.eyJpc3MiOiJodHRwczovL3Nzby5naXRnYWxzLmNvbS9hcHBsaWNhdGlvbi9vL3NlYnRlc3QvIiwic3ViIjoiZjJiNzIwOGY2MTcwYWI0NWNlZGM1OGUzMTM0NGNjNGY3MGQzZWRjMjhkYWZkMmJlNDZkNzIxMzM1ZDQxZDk2NCIsImF1ZCI6IkNMYUxyOHNpa0VpTjdOQ3JQTWhqaGJ0TFpnblpKNkpaVnpQZFZONVAiLCJleHAiOjE3MDM5NTgxMTgsImlhdCI6MTcwMzk0MDExOCwiYXV0aF90aW1lIjoxNzAzODU3NzMwLCJhY3IiOiJnb2F1dGhlbnRpay5pby9wcm92aWRlcnMvb2F1dGgyL2RlZmF1bHQiLCJlbWFpbCI6IiIsImVtYWlsX3ZlcmlmaWVkIjp0cnVlLCJuYW1lIjoiSW5zb21uaWEiLCJnaXZlbl9uYW1lIjoiSW5zb21uaWEiLCJwcmVmZXJyZWRfdXNlcm5hbWUiOiJpbnNvbW5pYS10ZXN0Iiwibmlja25hbWUiOiJpbnNvbW5pYS10ZXN0IiwiZ3JvdXBzIjpbXSwiYXpwIjoiQ0xhTHI4c2lrRWlON05DclBNaGpoYnRMWmduWko2SlpWelBkVk41UCIsInVpZCI6IjFpRnoySmVvV0IyMFlBOWpzcEZSdDJLTUVsQXJhZ0NtRnJwVUJhVE0ifQ.QWW2A4NGE3SGVLZsAYW0mVpopud3Pd-fua2F__0g7BHO7B6IDCSQGM786cOgk4E07Eq2dP8m2xM4O2Ok18ayyek2gYbg4uCHzZv3F1097njPspRfrJZH-MpExobV_6oBtAeAuQKopaSfGIPQE4cWJh32TKZFGHRPEMBz8W7GTPqDZcnzbu8zGHzb7tXhEUybjQFRKWU8jRIu8AiVDC8jyyqzTGJClVVd_gNUHY1vDB86lcJQHhJw2sEY9LjMv3O_ok9nJ-abzb2bJK133C1zWw9whrYOKeYCBNDC37I03m9eMnTi1YPPzi1woak_qC2JFcmCrcCbalrrruHdDwyWtyabH9s_YueZAEGyKZvLSLadx05xEAQ-aUHkKqr6hIYzPBw9vCmfhJ-UouRjFFP9FCxkNKTZ00_QUY-LQoYizTd0jENmjLZCRf8xo4iVmL5RtVwtJNoL8g_Mdpyn9JfKnPrhRQE3SqMVYQbF43XNInmVCP-acrezvOG5nwHZ4lWNgsjhYguhRM4eTx-B7IYx6x2Kqpbnj6Qte19FHfTS7cClGZ0eRpV55mUohSxdvEYGWsB-F_rprV4vxdcmw7kEpk8wtt6Nb4xX-NmTHiFUkKw2sio3wg-u5EziHhTqHZaldSTefnweoBJ1PB439Xww5a-x6xN6mE8DkEcc3xfAuXM";
let well_known_uri = "https://sso.gitgals.com/application/o/sebtest/.well-known/openid-configuration";
// Extract the x5c field from the JWKS
let x5c = "MIIFVDCCAzygAwIBAgIRAN2g0n7Cqki0kP4aDM1ON50wDQYJKoZIhvcNAQELBQAwHjEcMBoGA1UEAwwTYXV0aGVudGlrIDIwMjMuMTAuNDAeFw0yMzEyMjcxNDEwNDlaFw0yNDEyMjcxNDEwNDlaMFYxKjAoBgNVBAMMIWF1dGhlbnRpayBTZWxmLXNpZ25lZCBDZXJ0aWZpY2F0ZTESMBAGA1UECgwJYXV0aGVudGlrMRQwEgYDVQQLDAtTZWxmLXNpZ25lZDCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBAM2BP7UtRaTlM/KvE7E2S5GPdV88f/IUqxANoWS+JnWFSpRUXkkCorEUWo7LTrhNaaQni3FIdo2m2ouF9/+NlHj2038l1pNj/FPiZe8EyRbriQe/maKejq02CNW2rmD4cjWMK4h228o8QqeNSFxG11DEku4mN6Kz6X8Mi9iQWwTx0h8cl1Rxo/S6iBK9DZA1005DSkMskXGsN172O1cHZaG55WhmL6lKOcvvKyGwbccrrl9AufBz1SCoFZ/ERN/D5yRwehwjChP1mm3G4jzhiK/8LkmmnnfzNB01WoxZFzL9a+BXjEWWFyfRm+1rwEhrZ9DFqmPKA43XuPeRVijr3pZGUxH45WqSoXDv0luLLi0dTOUvgDETtj5ugVd+0Qi2cZX0W5Sh8ecEK6FwICRVYoRcd5fv4MfUwMlqT9S4+16B0TrEWkc6brfg9V3xGgNFRG3axCd68LAzP7ezPVGheubdNNnA/4HplxsFH8pjoyRiORSiK77IlLQ/MhngpJ9ExW/8xRkbl9o5bSAYTqtPPIOsSciMAlsipSLx+eUE4/VDcfhuaGf7Z2FSHfHvETwFhr+CDfaDHdgNbk2+ZXWWIqFbLxevrbHwj9YMtIuxagGrNTaAx1ZEizf9tZco5JDDsywFGvcL7oaHo4zx579gGGPgoWvHvzLejjg4hJL74vIzAgMBAAGjVTBTMFEGA1UdEQEB/wRHMEWCQ1JNa3diMFFMeDI5eXlManRvT0Zod1NPU1dEQVJhR3NjWmNvMk96NnMuc2VsZi1zaWduZWQuZ29hdXRoZW50aWsuaW8wDQYJKoZIhvcNAQELBQADggIBAKKSS0rA4gjn/g+LvSSoSr8H8PErLYQyHHTP4VfRXvk/o0drM2YJTrH53biHxXL92Ej9SRXKrrGcQlkVrucB79w6WHQUUmIVmm/CvYFbEKk7j2IbfR9CzKMMGzY7jrtf9YFyPPVQK5tIwA8uCaqXBu0zz5KSHTrXZLXXVV/xoikBTf1s5GN9MrnDK442xzf5cRBzQjpsa750MM2o5vEfRf2n9+HOuesAC56EaMiVQFGKELsx9Gmrjgley1X72H/5qgkLZb1o5+m4+9BAM8xSaowxC/DmH5ROryB8ctx7BGVZX4IEwHE9Q1G/6bfIeLr6bU/P+AgSzJv5Qan3e1jzmqB/2rmVxECfLEy5Pxmsa1FZNjleFK+8jj4qSKF+jiEMnmtv6V18EvIj5m4YcOjJpPjfq2saw0u9mP45wFERuEGpb7tWBEVLj+HirrmounCvaMr+m++oxaWaT3ECCwN8Sw5EtfXRZovzbW52Qj3HK0f8ip+EzurnWO+EJt6xBXgR0eRzNKSxPpGpZLuF8KUGLwOubMsDIO/+jRy3se/9jG9b9dz2rjgIxSYgnvSl55vqw0WMp6qoCqnXBB8+50Sn4Znc+/nApExFAgY7T5cE/q17CaryfmF2nkqANkYeCcduZ1qtSPnEsyxTaL9aerxyi9GMpfvriPdhNlwc1cos9CV3";