Skip to content

Commit

Permalink
fix: lower jwt clock skew from 5min to 30s
Browse files Browse the repository at this point in the history
  • Loading branch information
IvanJosipovic committed Jun 20, 2023
1 parent 6072fd9 commit d7df3fa
Showing 1 changed file with 2 additions and 0 deletions.
2 changes: 2 additions & 0 deletions src/oidc-guard/Program.cs
Original file line number Diff line number Diff line change
Expand Up @@ -55,10 +55,12 @@ public static void Main(string[] args)
o.NonceCookie.Name = settings.CookieName;
o.ResponseType = OpenIdConnectResponseType.Code;
o.SaveTokens = settings.SaveTokensInCookie;
o.TokenValidationParameters.ClockSkew = TimeSpan.FromSeconds(30);
})
.AddJwtBearer(o =>
{
o.MetadataAddress = settings.OpenIdProviderConfigurationUrl;
o.TokenValidationParameters.ClockSkew = TimeSpan.FromSeconds(30);
o.TokenValidationParameters.ValidateAudience = settings.ValidateAudience;
o.TokenValidationParameters.ValidateIssuer = settings.ValidateIssuer;
o.TokenValidationParameters.ValidIssuers = settings.ValidIssuers;
Expand Down

0 comments on commit d7df3fa

Please sign in to comment.