1*e7b1675dSTing-Kang Chang // Copyright 2021 Google LLC 2*e7b1675dSTing-Kang Chang // 3*e7b1675dSTing-Kang Chang // Licensed under the Apache License, Version 2.0 (the "License"); 4*e7b1675dSTing-Kang Chang // you may not use this file except in compliance with the License. 5*e7b1675dSTing-Kang Chang // You may obtain a copy of the License at 6*e7b1675dSTing-Kang Chang // 7*e7b1675dSTing-Kang Chang // http://www.apache.org/licenses/LICENSE-2.0 8*e7b1675dSTing-Kang Chang // 9*e7b1675dSTing-Kang Chang // Unless required by applicable law or agreed to in writing, software 10*e7b1675dSTing-Kang Chang // distributed under the License is distributed on an "AS IS" BASIS, 11*e7b1675dSTing-Kang Chang // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 12*e7b1675dSTing-Kang Chang // See the License for the specific language governing permissions and 13*e7b1675dSTing-Kang Chang // limitations under the License. 14*e7b1675dSTing-Kang Chang // 15*e7b1675dSTing-Kang Chang /////////////////////////////////////////////////////////////////////////////// 16*e7b1675dSTing-Kang Chang 17*e7b1675dSTing-Kang Chang #ifndef TINK_JWT_JWT_MAC_H_ 18*e7b1675dSTing-Kang Chang #define TINK_JWT_JWT_MAC_H_ 19*e7b1675dSTing-Kang Chang 20*e7b1675dSTing-Kang Chang #include <string> 21*e7b1675dSTing-Kang Chang 22*e7b1675dSTing-Kang Chang #include "absl/strings/string_view.h" 23*e7b1675dSTing-Kang Chang #include "tink/jwt/jwt_validator.h" 24*e7b1675dSTing-Kang Chang #include "tink/jwt/raw_jwt.h" 25*e7b1675dSTing-Kang Chang #include "tink/jwt/verified_jwt.h" 26*e7b1675dSTing-Kang Chang #include "tink/util/status.h" 27*e7b1675dSTing-Kang Chang #include "tink/util/statusor.h" 28*e7b1675dSTing-Kang Chang 29*e7b1675dSTing-Kang Chang namespace crypto { 30*e7b1675dSTing-Kang Chang namespace tink { 31*e7b1675dSTing-Kang Chang 32*e7b1675dSTing-Kang Chang /////////////////////////////////////////////////////////////////////////////// 33*e7b1675dSTing-Kang Chang // Interface for authenticating and verifying JWT with JWS MAC. 34*e7b1675dSTing-Kang Chang // 35*e7b1675dSTing-Kang Chang // Sees RFC 7519 and RFC 7515. Security guarantees: similar to MAC. 36*e7b1675dSTing-Kang Chang class JwtMac { 37*e7b1675dSTing-Kang Chang public: 38*e7b1675dSTing-Kang Chang // Computes a MAC and encodes the raw JWT token and the MAC in the JWS compact 39*e7b1675dSTing-Kang Chang // serialization format. 40*e7b1675dSTing-Kang Chang virtual crypto::tink::util::StatusOr<std::string> ComputeMacAndEncode( 41*e7b1675dSTing-Kang Chang const RawJwt& token) const = 0; 42*e7b1675dSTing-Kang Chang 43*e7b1675dSTing-Kang Chang // Verifies and decodes a JWT token in the JWS compact serialization format. 44*e7b1675dSTing-Kang Chang // 45*e7b1675dSTing-Kang Chang // The JWT is validated against the rules in validator. That is, every claim 46*e7b1675dSTing-Kang Chang // in validator must also be present in the JWT. For example, if validator 47*e7b1675dSTing-Kang Chang // contains an issuer (iss) claim, the JWT must contain an identical claim. 48*e7b1675dSTing-Kang Chang // The JWT can contain claims that are NOT in the validator. However, if the 49*e7b1675dSTing-Kang Chang // JWT contains a list of audiences, the validator must also contain an 50*e7b1675dSTing-Kang Chang // audience in the list. 51*e7b1675dSTing-Kang Chang // 52*e7b1675dSTing-Kang Chang // If the JWT contains timestamp claims such as expiration (exp), issued_at 53*e7b1675dSTing-Kang Chang // (iat) or not_before (nbf), they will also be validated. validator allows to 54*e7b1675dSTing-Kang Chang // set a clock skew, to deal with small clock differences among different 55*e7b1675dSTing-Kang Chang // machines. 56*e7b1675dSTing-Kang Chang virtual crypto::tink::util::StatusOr<VerifiedJwt> VerifyMacAndDecode( 57*e7b1675dSTing-Kang Chang absl::string_view compact, const JwtValidator& validator) const = 0; 58*e7b1675dSTing-Kang Chang 59*e7b1675dSTing-Kang Chang virtual ~JwtMac() = default; 60*e7b1675dSTing-Kang Chang }; 61*e7b1675dSTing-Kang Chang 62*e7b1675dSTing-Kang Chang } // namespace tink 63*e7b1675dSTing-Kang Chang } // namespace crypto 64*e7b1675dSTing-Kang Chang 65*e7b1675dSTing-Kang Chang #endif // TINK_JWT_JWT_MAC_H_ 66