Files
alterminal/internal/jwk/jwk.go
T

27 lines
1.2 KiB
Go
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
// Package jwk 提供簽發 JWT(ID Token/Access Token)所用金鑰的資料模型,
// 以及其 RFC 7517 JWK/JWKS 公開表示法,供 /.well-known/jwks.json 發佈。
package jwk
// JWK 參數的註冊值(RFC 7517 的 kty/use、RFC 7518 的 alg)。
const (
KeyTypeRSA = "RSA" // kty:金鑰類型
KeyUseSig = "sig" // use:簽章用途
AlgRS256 = "RS256" // alg:RSASSA-PKCS1-v1_5 搭配 SHA-256
)
// JWK 為單一把金鑰的公開形式(RFC 7517),僅含 RP 驗證 JWT 簽章所需的
// 參數;私有參數(d、p、q、dp、dq、qi)依規範與安全考量絕不序列化。
type JWK struct {
Kty string `json:"kty"` // 金鑰類型(RSA)
Use string `json:"use"` // 用途(sig)
Kid string `json:"kid"` // 金鑰 ID,對應 JWT header 的 kid
Alg string `json:"alg,omitempty"` // 建議演算法(RS256)
N string `json:"n"` // RSA modulus,base64url 無填充
E string `json:"e"` // RSA 公開指數,同上(65537 時為 "AQAB")
}
// JWKS 為 JWK Set(RFC 7517 §5),/.well-known/jwks.json 的回應格式。
type JWKS struct {
Keys []JWK `json:"keys"`
}