Replies: 1 comment 2 replies
-
This only opens you up to someone being able to force your process to always reload. You don't need anything but the verify and remotejwks "instance". |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Hello! I've read through #394 and would like to make sure I'm understanding the pattern correctly for invalidating cached remote keys. In my case, the authorization service does not rotate keys regularly. A new key set is only published if the keys are compromised.
Thanks for the great library!
Beta Was this translation helpful? Give feedback.
All reactions