xref: /aosp_15_r20/external/tink/cc/jwt/jwt_validator.h (revision e7b1675dde1b92d52ec075b0a92829627f2c52a5)
1*e7b1675dSTing-Kang Chang // Copyright 2021 Google LLC
2*e7b1675dSTing-Kang Chang //
3*e7b1675dSTing-Kang Chang // Licensed under the Apache License, Version 2.0 (the "License");
4*e7b1675dSTing-Kang Chang // you may not use this file except in compliance with the License.
5*e7b1675dSTing-Kang Chang // You may obtain a copy of the License at
6*e7b1675dSTing-Kang Chang //
7*e7b1675dSTing-Kang Chang //     http://www.apache.org/licenses/LICENSE-2.0
8*e7b1675dSTing-Kang Chang //
9*e7b1675dSTing-Kang Chang // Unless required by applicable law or agreed to in writing, software
10*e7b1675dSTing-Kang Chang // distributed under the License is distributed on an "AS IS" BASIS,
11*e7b1675dSTing-Kang Chang // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12*e7b1675dSTing-Kang Chang // See the License for the specific language governing permissions and
13*e7b1675dSTing-Kang Chang // limitations under the License.
14*e7b1675dSTing-Kang Chang //
15*e7b1675dSTing-Kang Chang ///////////////////////////////////////////////////////////////////////////////
16*e7b1675dSTing-Kang Chang 
17*e7b1675dSTing-Kang Chang #ifndef TINK_JWT_JWT_VALIDATOR_H_
18*e7b1675dSTing-Kang Chang #define TINK_JWT_JWT_VALIDATOR_H_
19*e7b1675dSTing-Kang Chang 
20*e7b1675dSTing-Kang Chang #include <string>
21*e7b1675dSTing-Kang Chang 
22*e7b1675dSTing-Kang Chang #include "absl/strings/string_view.h"
23*e7b1675dSTing-Kang Chang #include "absl/time/clock.h"
24*e7b1675dSTing-Kang Chang #include "absl/time/time.h"
25*e7b1675dSTing-Kang Chang #include "tink/jwt/raw_jwt.h"
26*e7b1675dSTing-Kang Chang #include "tink/util/status.h"
27*e7b1675dSTing-Kang Chang #include "tink/util/statusor.h"
28*e7b1675dSTing-Kang Chang 
29*e7b1675dSTing-Kang Chang namespace crypto {
30*e7b1675dSTing-Kang Chang namespace tink {
31*e7b1675dSTing-Kang Chang 
32*e7b1675dSTing-Kang Chang ///////////////////////////////////////////////////////////////////////////////
33*e7b1675dSTing-Kang Chang // A JwtValidator defines how JSON Web Tokens (JWTs) should be validated.
34*e7b1675dSTing-Kang Chang //
35*e7b1675dSTing-Kang Chang 
36*e7b1675dSTing-Kang Chang class JwtValidatorBuilder;
37*e7b1675dSTing-Kang Chang 
38*e7b1675dSTing-Kang Chang class JwtValidator {
39*e7b1675dSTing-Kang Chang  public:
40*e7b1675dSTing-Kang Chang   // JwtValidator objects are copiable and movable.
41*e7b1675dSTing-Kang Chang   JwtValidator(const JwtValidator&) = default;
42*e7b1675dSTing-Kang Chang   JwtValidator& operator=(const JwtValidator&) = default;
43*e7b1675dSTing-Kang Chang   JwtValidator(JwtValidator&& other) = default;
44*e7b1675dSTing-Kang Chang   JwtValidator& operator=(JwtValidator&& other) = default;
45*e7b1675dSTing-Kang Chang 
46*e7b1675dSTing-Kang Chang   util::Status Validate(crypto::tink::RawJwt const& raw_jwt) const;
47*e7b1675dSTing-Kang Chang 
48*e7b1675dSTing-Kang Chang  private:
49*e7b1675dSTing-Kang Chang   util::Status ValidateTimestamps(crypto::tink::RawJwt const& raw_jwt) const;
50*e7b1675dSTing-Kang Chang   util::Status ValidateTypeHeader(crypto::tink::RawJwt const& raw_jwt) const;
51*e7b1675dSTing-Kang Chang   util::Status ValidateIssuer(crypto::tink::RawJwt const& raw_jwt) const;
52*e7b1675dSTing-Kang Chang   util::Status ValidateAudiences(crypto::tink::RawJwt const& raw_jwt) const;
53*e7b1675dSTing-Kang Chang   explicit JwtValidator(const JwtValidatorBuilder& builder);
54*e7b1675dSTing-Kang Chang   friend class JwtValidatorBuilder;
55*e7b1675dSTing-Kang Chang   absl::optional<std::string> expected_type_header_;
56*e7b1675dSTing-Kang Chang   absl::optional<std::string> expected_issuer_;
57*e7b1675dSTing-Kang Chang   absl::optional<std::string> expected_audience_;
58*e7b1675dSTing-Kang Chang   bool ignore_type_header_;
59*e7b1675dSTing-Kang Chang   bool ignore_issuer_;
60*e7b1675dSTing-Kang Chang   bool ignore_audiences_;
61*e7b1675dSTing-Kang Chang   bool allow_missing_expiration_;
62*e7b1675dSTing-Kang Chang   bool expect_issued_in_the_past_;
63*e7b1675dSTing-Kang Chang   absl::Duration clock_skew_;
64*e7b1675dSTing-Kang Chang   absl::optional<absl::Time> fixed_now_;
65*e7b1675dSTing-Kang Chang };
66*e7b1675dSTing-Kang Chang 
67*e7b1675dSTing-Kang Chang class JwtValidatorBuilder {
68*e7b1675dSTing-Kang Chang  public:
69*e7b1675dSTing-Kang Chang   JwtValidatorBuilder();
70*e7b1675dSTing-Kang Chang 
71*e7b1675dSTing-Kang Chang   // JwtValidatorBuilder objects are copiable and movable.
72*e7b1675dSTing-Kang Chang   JwtValidatorBuilder(const JwtValidatorBuilder&) = default;
73*e7b1675dSTing-Kang Chang   JwtValidatorBuilder& operator=(const JwtValidatorBuilder&) = default;
74*e7b1675dSTing-Kang Chang   JwtValidatorBuilder(JwtValidatorBuilder&& other) = default;
75*e7b1675dSTing-Kang Chang   JwtValidatorBuilder& operator=(JwtValidatorBuilder&& other) = default;
76*e7b1675dSTing-Kang Chang 
77*e7b1675dSTing-Kang Chang   JwtValidatorBuilder& ExpectTypeHeader(absl::string_view expected_type_header);
78*e7b1675dSTing-Kang Chang   JwtValidatorBuilder& ExpectIssuer(absl::string_view expected_issuer);
79*e7b1675dSTing-Kang Chang   JwtValidatorBuilder& ExpectAudience(absl::string_view expected_audience);
80*e7b1675dSTing-Kang Chang 
81*e7b1675dSTing-Kang Chang   JwtValidatorBuilder& IgnoreTypeHeader();
82*e7b1675dSTing-Kang Chang   JwtValidatorBuilder& IgnoreIssuer();
83*e7b1675dSTing-Kang Chang   JwtValidatorBuilder& IgnoreAudiences();
84*e7b1675dSTing-Kang Chang 
85*e7b1675dSTing-Kang Chang   JwtValidatorBuilder& AllowMissingExpiration();
86*e7b1675dSTing-Kang Chang   JwtValidatorBuilder& ExpectIssuedInThePast();
87*e7b1675dSTing-Kang Chang 
88*e7b1675dSTing-Kang Chang   JwtValidatorBuilder& SetClockSkew(absl::Duration clock_skew);
89*e7b1675dSTing-Kang Chang   JwtValidatorBuilder& SetFixedNow(absl::Time fixed_now);
90*e7b1675dSTing-Kang Chang 
91*e7b1675dSTing-Kang Chang   util::StatusOr<JwtValidator> Build();
92*e7b1675dSTing-Kang Chang 
93*e7b1675dSTing-Kang Chang  private:
94*e7b1675dSTing-Kang Chang   friend class JwtValidator;
95*e7b1675dSTing-Kang Chang   absl::optional<std::string> expected_type_header_;
96*e7b1675dSTing-Kang Chang   absl::optional<std::string> expected_issuer_;
97*e7b1675dSTing-Kang Chang   absl::optional<std::string> expected_audience_;
98*e7b1675dSTing-Kang Chang   bool ignore_type_header_;
99*e7b1675dSTing-Kang Chang   bool ignore_issuer_;
100*e7b1675dSTing-Kang Chang   bool ignore_audiences_;
101*e7b1675dSTing-Kang Chang   bool allow_missing_expiration_;
102*e7b1675dSTing-Kang Chang   bool expect_issued_in_the_past_;
103*e7b1675dSTing-Kang Chang   absl::Duration clock_skew_;
104*e7b1675dSTing-Kang Chang   absl::optional<absl::Time> fixed_now_;
105*e7b1675dSTing-Kang Chang };
106*e7b1675dSTing-Kang Chang 
107*e7b1675dSTing-Kang Chang }  // namespace tink
108*e7b1675dSTing-Kang Chang }  // namespace crypto
109*e7b1675dSTing-Kang Chang 
110*e7b1675dSTing-Kang Chang #endif  // TINK_JWT_JWT_VALIDATOR_H_
111