Static ReadonlyDEFINED_The claims section 3.1 defines, which a crit may not name.
Static ReadonlyTYPThe typ of each federation JWT this service makes or reads, by name.
StaticacceptedLists the algorithms a federation signature may use: every asymmetric one
crypto.js implements, never an HMAC and never none.
the algorithm names
StaticconfigurationAnswers an Entity Identifier's configuration endpoint (9): a trailing "/"
removed, then /.well-known/openid-federation appended.
the Entity Identifier
the URL
StaticdecodeReads a compact JWS without verifying it.
the JWT
{ ok, header, claims }, or { ok: false, code, why }
StaticisAnswers whether a value is a federation endpoint URL (5.1.1): https, with no fragment.
the value
true for an endpoint URL
StaticisAnswers whether a value is an Entity Identifier (1.2): an https URL with a host and no query, fragment or user information.
the value
true for an Entity Identifier
StaticjwksChecks that a JWK Set has a unique, non-empty kid on every key (3.1.1).
the JWK Set
the problem, or '' when there is none
StaticmetadataChecks the syntax of a metadata claim (5, 3.2): objects keyed by entity
type, no null member, no JWK Set parameter under federation_entity, and
every federation endpoint there an https URL without a fragment.
the claim
the problem, or '' when it is well formed
StaticsignSigns a typed federation JWT with a Federation Entity Key; the header is
typ, the signer's algorithm and its kid, never x5c or x5t.
the claims, signed as given (the caller sets iat and
exp)
the JWT's typ
the private key, its algorithm and its kid
the compact JWS
StatictimeChecks a claim set's times (3.2): iat not in the future and exp not in
the past, each with leeway.
the claims
the time now, in seconds
the leeway, in seconds
OptionalexpOptional: boolean
whether exp may be absent, as for a Trust Mark
the problem, or '' when both hold
StatictrustChecks the syntax of trust_marks (3.1.2, 3.2): each object's
trust_mark_type equals that of the Trust Mark JWT it carries. Whether a
mark is trusted is decided elsewhere.
the claim
the problem, or '' when it is well formed
StaticvalidateValidates an Entity Statement's claims on their own (3.1, 3.2); the kind
follows from the claims (iss == sub is an Entity Configuration).
the claims
nowSec, skewSec, understood (claim names a crit
may name) and audience (only for an explicit registration request)
{ ok, claims }, or the first problem found with its code
StaticverifyVerifies a typed JWT against a JWK Set: the typ exact, the algorithm
asymmetric, the kid naming exactly one key of the set, and the signature.
the JWT
the JWK Set the caller trusts for it
the typ it must carry
{ ok, header, claims, key }, or { ok: false, code, why }
The six typed JWTs of OpenID Federation 1.1, made and read: the
typexact, the algorithm asymmetric, thekidnaming a key in the JWK Set it is checked against, and the signaturecommon/crypto.js's. Which JWK Set to trust is always the caller's decision. A library of static methods.