Monorepo for Tangled โ€” https://tangled.org

appview/oauth: use client attestation #721

merged
opened by oppi.li targeting master from push-qryntruoqzmt

this change makes our tangled appview a "confidential" client.

this change includes breaking changes to the appview service, it now requires two different environment variables:

  • TANGLED_OAUTH_CLIENT_SECRET: the secret component of the old JWKs object
  • TANGLED_OAUTH_CLIENT_KID: the key ID the old JWKs object

both of these can be extracted from the old JWKs object: obj.d and obj.kid respectively.

Signed-off-by: oppiliappan me@oppi.li

0
by oppi.li 2 comments
expand 1 commit
appview/oauth: use client attestation
1
by oppi.li 0 comments
expand 1 commit
appview/oauth: use client attestation
Labels

None yet.

assignee

None yet.

Participants 2
AT URI
at://did:plc:qfpnj4og54vl56wngdriaxug/sh.tangled.repo.pull/3m4bdyfrbw222