Azure-Samples / Azure-Samples/remote-mcp-apim-functions-python

JWT has an invalid signature

Abierto
#18 5 comentarios 0 reacciones 0 asignados Ver en GitHub
Lenguaje dominante
Bicep
Estrellas
129
Forks
79
Métricas de merge de PR
Sin PR fusionados en 30 d

Descripción

The access token stored in the APIM cache which is mapped to session key has an invalid signature. Though the JWT itself is valid, however, does not have any valid signature and it is causing the issue at various downstream levels where JWT validation failing.

![Image](https://github.com/user-attachments/assets/4ca099ed-f28e-4e8e-8666-39753b4e0a99)

![Image](https://github.com/user-attachments/assets/65c265b3-41b4-46ae-9213-c8a20bb5ec0e)

Further using the token in exchange flows through MSAL or Azure.Identity also deems the signature invalid -

![Image](https://github.com/user-attachments/assets/b31c67e6-c7be-47eb-9d01-4a75c37c424b)

Is it because we are assigned APIMGatewayURL as an issuer while the issuer in the token is different (https://sts.windows.net/tenantId) ?
@prjhawar @jukasper - Kindly help with this issue.

Guía de contribución

Abrir la guía de contribución

Línea de trabajo

No se especifica ningún archivo fuente, prueba ni punto de entrada. Empieza comparando la configuración del issuer de APIM con los claims de issuer y signature del token almacenado en caché, y después sigue la validación a través de MSAL o Azure.Identity; se considera terminado cuando se haya identificado el issuer/signature mismatch y exista un fix confirmado para la configuración o el flujo afectado.

Escrito por el modelo de indexación a partir del texto del issue.

Evaluación

Stack tecnológico
azure
Área
api, authentication, cloud, security
Tipo de issue
Error
Dificultad
4/5
Tiempo estimado
3-5 días
Estado de actividad
Estancado
Claridad
Necesita aclaración
Aptitud para principiantes
20/100

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.