Ghost/ghost
Naz 9756094ae2 🐛 Fixed signing key mismatching in JWT/JWKS
refs https://github.com/TryGhost/Team/issues/1640
closes https://github.com/TryGhost/Members/pull/401/
refs https://forum.ghost.org/t/ghost-jwt-question-possible-bug/30210

- Without `keyid` parameter some of the clien libraries were not able to match the signin key to verify JWT
- Missing `keyid` parameter allows to indicate the key used to secure JWS (as per https://www.rfc-editor.org/rfc/rfc7515#section-4.1.4) and resolves the automatic matching issue on the client.
- The `kid` parameter was left in claims to avoid accidental breaking changes.
2022-05-23 18:45:08 +08:00
..
domain-events Published new versions 2022-05-16 19:29:05 +01:00
express-dynamic-redirects Published new versions 2022-05-16 19:29:05 +01:00
magic-link Published new versions 2022-05-16 19:29:05 +01:00
member-analytics-service Published new versions 2022-05-16 19:29:05 +01:00
member-events Published new versions 2022-05-16 19:29:05 +01:00
members-analytics-ingress Published new versions 2022-05-16 19:29:05 +01:00
members-api 🐛 Fixed signing key mismatching in JWT/JWKS 2022-05-23 18:45:08 +08:00
members-csv Published new versions 2022-05-19 18:11:03 +02:00
members-events-service Published new versions 2022-05-16 19:29:05 +01:00
members-importer Published new versions 2022-05-19 18:11:03 +02:00
members-ssr Published new versions 2022-05-16 19:29:05 +01:00
offers Published new versions 2022-05-16 19:29:05 +01:00
payments Published new versions 2022-05-16 19:29:05 +01:00
stripe Published new versions 2022-05-16 19:29:05 +01:00
verification-trigger Published new versions 2022-05-16 19:29:05 +01:00