Azure-Samples / Azure-Samples/remote-mcp-apim-functions-python

JWT has an invalid signature

Đang mở
#18 5 bình luận 0 reaction 0 người được giao Xem trên GitHub
Ngôn ngữ chính
Bicep
Star
129
Fork
79
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Mô tả

The access token stored in the APIM cache which is mapped to session key has an invalid signature. Though the JWT itself is valid, however, does not have any valid signature and it is causing the issue at various downstream levels where JWT validation failing.

![Image](https://github.com/user-attachments/assets/4ca099ed-f28e-4e8e-8666-39753b4e0a99)

![Image](https://github.com/user-attachments/assets/65c265b3-41b4-46ae-9213-c8a20bb5ec0e)

Further using the token in exchange flows through MSAL or Azure.Identity also deems the signature invalid -

![Image](https://github.com/user-attachments/assets/b31c67e6-c7be-47eb-9d01-4a75c37c424b)

Is it because we are assigned APIMGatewayURL as an issuer while the issuer in the token is different (https://sts.windows.net/tenantId) ?
@prjhawar @jukasper - Kindly help with this issue.

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.