diff --git a/oidc/verify.go b/oidc/verify.go index a9c2537b..395ad6c7 100644 --- a/oidc/verify.go +++ b/oidc/verify.go @@ -272,7 +272,7 @@ func (v *IDTokenVerifier) Verify(ctx context.Context, rawIDToken string) (*IDTok // Set to 5 minutes by default since this is what other OpenID Connect providers do to deal with clock skew. // https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/blob/6.12.2/src/Microsoft.IdentityModel.Tokens/TokenValidationParameters.cs#L149-L153 - clockSkew := time.Duration(5) * time.Minute + clockSkew := 5 * time.Minute if v.config.ClockSkew != nil { clockSkew = v.config.ClockSkew() }