mirror of
https://github.com/windmill-labs/windmill.git
synced 2026-09-07 08:02:40 +00:00
parse_jwks_keys filtered on metadata only (kty/alg/use/key_ops), but jsonwebtoken carries n/e/x/y as strings and defers decoding to auth time, so a JWKS whose only key had malformed material passed save-time validation and every token failed later. Keep a key only if DecodingKey::from_jwk decodes it. This is the single source for both edit_guest_jwt_key and per-request verify. Update two test comments that credited the SPKI parse alone now that the guard also accepts a PKCS#1 RSA public key. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01VF3v6LA9399gNphmZaHYG3