jwt
This module is available to use in your EdgeWorkers code bundles to verify JWT tokens using digital signatures. This module considers JWT tokens as defined in the RFC-7519 standards document. It exports implementations of the JWTValidator class that contains functions to validate JWT tokens.
You can import the jwt module from the EdgeWorkers GitHub repo.
JWTValidator
Constructor for new JWTValidator Object. It performs type checks on the jwtOptions Object fields.
JWTOptions Object
JWTJson
Holds JWTHeader and JWTPayload in JSON format.
JWTHeader
JWTPayload
async validate()
Decodes the base64 url encoded token, applies JWT default rules, and performs signature verification using keys. Returns a Promise<JWTJson> .
The following default rules apply to signature verification.
- A token should have a header and a payload. JWT tokens secured in a valid base64 format should also have a signature.
- If you enable issuer verification, the issuer string needs to match the
issclaim. - If you enable subject verification, the subject string needs to match the
subfield. - If you enable audience verification, the audience string needs to match the
audfield. - Set
ignoreExpirationto false, to validate the JWTexpfield. - Set
ignoreNotBeforeto false, to validate the JWTnbffield.
Exceptions
Throws an error with appropriate message if type checks fails for arguments.
👍 You can configure the validation options using the
jwtOptionsparameter. You will only receive validation errors for options that you have enabled. | Error | Description | | --- | --- | | Error(Invalid token type, expected string!) | Argument type check fails. | | Error(Invalid hex string) | Key passed is not valid hex format. | | Error(InvalidLengthError: JWT signature is not correctly encoded) | The JWT signature is not valid base64url encoded. | | Error(JWT malformed: invalid iss, expected ${jwtOptions.issuer}) | Issuer validation does not match theissfield from the JWT payload. | | Error(JWT malformed: invalid sub, expected ${jwtOptions.subject}) | Subject validation does not match thesubfield from the JWT payload. | | Error(JWT malformed: invalid aud, expected ${jwtOptions.audience}) | Audience validation is not present in theaudfield from the JWT payload. | | Error(JWT malformed: exp must be number) | Expiry validation type checks fail for theexpfield from the JWT payload. | | Error(JWT expired) | You have enabled expiry validation and the token is expired. | | Error(JWT malformed: nbf must be number) | Not before validation type checks fail for thenbffield from the JWT payload. | | Error(JWT not active) | You have enabled not before validation and the token is not active. | | DOMException or TypeError | This error occurs if:
- You try to use invalid key data.
- The key is not an accepted key for the algorithm.
- You try to use an algorithm that is either unknown or isn’t suitable for a verify operation. |