Skip to content

Commit 3a93de3

Browse files
author
MPCoreDeveloper
committed
docs(JwtBearer): precise wording on runtime metadata logging (LKG nuance) + demo --broken switch
1 parent db93dab commit 3a93de3

1 file changed

Lines changed: 8 additions & 4 deletions

File tree

‎src/SafeWebCore.JwtBearer/README.md‎

Lines changed: 8 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -135,18 +135,22 @@ one line per refresh interval. Requires `AddJwtBearerHardening`/`AddSafeWebCoreJ
135135
- success → `Information`. Nothing else changes.
136136
2. **`JwtBearerHardeningApplication`** applies the token-validation defaults and chains claim checks
137137
(`typ`, `jti`, `nbf`, `iat`, maximum lifetime) onto your existing `OnTokenValidated` handler.
138-
3. **`LoggingConfigurationManager`** decorates the manager so metadata failures stay loud after startup.
138+
3. **`LoggingConfigurationManager`** decorates the manager so metadata failures that actually surface
139+
(no usable cached configuration) are logged at `Error`/`Warning` during runtime, not just at startup.
139140

140141
## Reproduce it yourself
141142

142143
The repository includes [**`examples/JwtBearerDemo`**](../../examples/JwtBearerDemo/) — a copy of
143144
Stephan's exact reproduction (misspelled `organisations` authority, his exact token-validation
144-
settings) with a one-boolean switch between the broken and the fixed behavior.
145+
settings) with a `--broken` switch between the broken and the fixed behavior.
145146

146147
## Limitations
147148

148-
- The guard validates the authority **once at startup**. If the identity provider goes down *after*
149-
startup, the runtime metadata logging (Option 2/3) keeps you informed; requests fail closed regardless.
149+
- The guard validates the authority **once at startup**; requests keep failing closed (401) whenever
150+
tokens cannot be validated. The runtime metadata logging (Option 2/3) reports retrieval failures
151+
that **surface** — once IdentityModel has loaded a healthy configuration, its last-known-good
152+
behavior serves the cached metadata without throwing, so an identity-provider outage *after* a
153+
healthy start produces no Error log (requests are unaffected while the cached config is valid).
150154
- The metadata is fetched one extra time at startup (which also warms the configuration cache).
151155
- `AddJwtBearerHardening` must be registered **after** `AddJwtBearer`.
152156

0 commit comments

Comments
 (0)