Expand description
Cloudflare Access JWT validation.
Behind a tunnel, Access forwards every authenticated request with a signed
assertion in Cf-Access-Jwt-Assertion. Checking it at the origin means a
request that reaches the loopback port some other way (a second tunnel, a
local process) is still refused. RS256 only; keys come from the team’s
JWKS, cached for an hour, refetched when an unknown kid shows up, and
refetched at most once per REFETCH_MIN so a flood of made-up key ids
cannot be turned into a flood of requests to Cloudflare.
Structs§
- Access
Validator - Verifies Access assertions for one application audience.
- Denied
- Why an assertion was refused. Logged, never sent to the client.
- Identity
- The verified caller behind an Access assertion.
Constants§
- ASSERTION_
HEADER - REFETCH_
MIN - The least time between two JWKS fetches.
Functions§
- normalize_
team_ domain - Normalize a team domain into the issuer string Access puts in
iss.
Type Aliases§
- Jwks
Fetcher - Fetches the JWKS document at a URL. Injectable so tests run offline.