iya-sts
    Preparing search index...

    The six typed JWTs of OpenID Federation 1.1, made and read: the typ exact, the algorithm asymmetric, the kid naming a key in the JWK Set it is checked against, and the signature common/crypto.js's. Which JWK Set to trust is always the caller's decision. A library of static methods.

    Index
    DEFINED_CLAIMS: readonly string[] = DEFINED_CLAIMS

    The claims section 3.1 defines, which a crit may not name.

    TYP: Readonly<
        {
            ENTITY_EVENTS_STATEMENT: "entity-events-statement+jwt";
            ENTITY_STATEMENT: "entity-statement+jwt";
            EXPLICIT_REGISTRATION_RESPONSE: "explicit-registration-response+jwt";
            JWK_SET: "jwk-set+jwt";
            RESOLVE_RESPONSE: "resolve-response+jwt";
            TRUST_MARK: "trust-mark+jwt";
            TRUST_MARK_DELEGATION: "trust-mark-delegation+jwt";
            TRUST_MARK_STATUS: "trust-mark-status-response+jwt";
        },
    > = TYP

    The typ of each federation JWT this service makes or reads, by name.

    • Lists the algorithms a federation signature may use: every asymmetric one crypto.js implements, never an HMAC and never none.

      Returns string[]

      the algorithm names

    • Answers an Entity Identifier's configuration endpoint (9): a trailing "/" removed, then /.well-known/openid-federation appended.

      Parameters

      • entityId: string

        the Entity Identifier

      Returns string

      the URL

    • Reads a compact JWS without verifying it.

      Parameters

      • jwt: any

        the JWT

      Returns Read

      { ok, header, claims }, or { ok: false, code, why }

    • Answers whether a value is a federation endpoint URL (5.1.1): https, with no fragment.

      Parameters

      • value: any

        the value

      Returns boolean

      true for an endpoint URL

    • Answers whether a value is an Entity Identifier (1.2): an https URL with a host and no query, fragment or user information.

      Parameters

      • value: any

        the value

      Returns boolean

      true for an Entity Identifier

    • Checks that a JWK Set has a unique, non-empty kid on every key (3.1.1).

      Parameters

      • jwks: any

        the JWK Set

      Returns string

      the problem, or '' when there is none

    • Checks the syntax of a metadata claim (5, 3.2): objects keyed by entity type, no null member, no JWK Set parameter under federation_entity, and every federation endpoint there an https URL without a fragment.

      Parameters

      • metadata: any

        the claim

      Returns string

      the problem, or '' when it is well formed

    • Signs a typed federation JWT with a Federation Entity Key; the header is typ, the signer's algorithm and its kid, never x5c or x5t.

      Parameters

      • payload: any

        the claims, signed as given (the caller sets iat and exp)

      • typ: string

        the JWT's typ

      • signer: Signer

        the private key, its algorithm and its kid

      Returns string

      the compact JWS

    • Checks a claim set's times (3.2): iat not in the future and exp not in the past, each with leeway.

      Parameters

      • claims: any

        the claims

      • nowSec: number

        the time now, in seconds

      • skewSec: number

        the leeway, in seconds

      • OptionalexpOptional: boolean

        whether exp may be absent, as for a Trust Mark

      Returns string

      the problem, or '' when both hold

    • Checks the syntax of trust_marks (3.1.2, 3.2): each object's trust_mark_type equals that of the Trust Mark JWT it carries. Whether a mark is trusted is decided elsewhere.

      Parameters

      • marks: any

        the claim

      Returns string

      the problem, or '' when it is well formed

    • Validates an Entity Statement's claims on their own (3.1, 3.2); the kind follows from the claims (iss == sub is an Entity Configuration).

      Parameters

      • claims: any

        the claims

      • options: any

        nowSec, skewSec, understood (claim names a crit may name) and audience (only for an explicit registration request)

      Returns Read

      { ok, claims }, or the first problem found with its code

    • Verifies a typed JWT against a JWK Set: the typ exact, the algorithm asymmetric, the kid naming exactly one key of the set, and the signature.

      Parameters

      • jwt: any

        the JWT

      • jwks: any

        the JWK Set the caller trusts for it

      • typ: string

        the typ it must carry

      Returns Read

      { ok, header, claims, key }, or { ok: false, code, why }