Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions extensions/jwt/CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,9 @@
# Changelog

## [Unreleased]

- Fixed: the JWKS host cache never expired, so `poll_interval` only re-read the key set fetched at startup and a provider key rotation was not picked up until the gateway restarted. The cache entry now lives for `poll_interval`.

## [1.3.0] - 2025-07-15

- Added support for static headers returned with 401 responses.
Expand Down
8 changes: 7 additions & 1 deletion extensions/jwt/src/lib.rs
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,13 @@ impl AuthenticationExtension for Jwt {
let config: Config = config.deserialize()?;

Ok(Self {
jwks_cache: Cache::builder("jwks", 1).timeout(config.poll_interval).build(),
// `timeout` bounds the wait for a concurrent fetch; it is not the entry lifetime. Without a
// TTL the JWKS fetched at startup lives for the whole process, so a provider key rotation is
// invisible until a restart and every token signed by the new key is rejected with a 401.
// Expire the entry after `poll_interval`, which is what the README promises.
jwks_cache: Cache::builder("jwks", 1)
.time_to_live(Some(config.poll_interval))
.build(),
jwks: None,
config,
})
Expand Down