Skip to main content

Module access

Module access 

Source
Expand description

Cloudflare Access JWT validation.

Behind a tunnel, Access forwards every authenticated request with a signed assertion in Cf-Access-Jwt-Assertion. Checking it at the origin means a request that reaches the loopback port some other way (a second tunnel, a local process) is still refused. RS256 only; keys come from the team’s JWKS, cached for an hour, refetched when an unknown kid shows up, and refetched at most once per REFETCH_MIN so a flood of made-up key ids cannot be turned into a flood of requests to Cloudflare.

Structs§

AccessValidator
Verifies Access assertions for one application audience.
Denied
Why an assertion was refused. Logged, never sent to the client.
Identity
The verified caller behind an Access assertion.

Constants§

ASSERTION_HEADER
REFETCH_MIN
The least time between two JWKS fetches.

Functions§

normalize_team_domain
Normalize a team domain into the issuer string Access puts in iss.

Type Aliases§

JwksFetcher
Fetches the JWKS document at a URL. Injectable so tests run offline.