Azure-Samples / Azure-Samples/remote-mcp-apim-functions-python

JWT has an invalid signature

Offen
#18 5 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
Vorherrschende Sprache
Bicep
Sterne
129
Forks
79
PR-Merge-Kennzahlen
Keine gemergten PRs in 30 T.

Beschreibung

The access token stored in the APIM cache which is mapped to session key has an invalid signature. Though the JWT itself is valid, however, does not have any valid signature and it is causing the issue at various downstream levels where JWT validation failing.

![Image](https://github.com/user-attachments/assets/4ca099ed-f28e-4e8e-8666-39753b4e0a99)

![Image](https://github.com/user-attachments/assets/65c265b3-41b4-46ae-9213-c8a20bb5ec0e)

Further using the token in exchange flows through MSAL or Azure.Identity also deems the signature invalid -

![Image](https://github.com/user-attachments/assets/b31c67e6-c7be-47eb-9d01-4a75c37c424b)

Is it because we are assigned APIMGatewayURL as an issuer while the issuer in the token is different (https://sts.windows.net/tenantId) ?
@prjhawar @jukasper - Kindly help with this issue.

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

No source file, test, or entry point is named. Start by comparing the APIM issuer configuration with the issuer and signature claims in the cached token, then trace validation through MSAL or Azure.Identity; done means the issuer/signature mismatch is identified and the affected configuration or flow has a confirmed fix.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
azure
Bereich
api, authentication, cloud, security
Issue-Typ
Bug
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Veraltet
Klarheit
Muss geklärt werden
Anfängerfreundlichkeit
20/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.