diff --git a/tools/auth/internal/jwk/jwk.go b/tools/auth/internal/jwk/jwk.go index 9de51fc2..27a1adec 100644 --- a/tools/auth/internal/jwk/jwk.go +++ b/tools/auth/internal/jwk/jwk.go @@ -114,12 +114,12 @@ func Fetch(ctx context.Context, jwksURL string, kid string) (*JWK, error) { } for _, key := range jwks.Keys { - if key.Kid == kid { + if key.Kid == kid && key.Alg != "" { return key, nil } } - return nil, fmt.Errorf("JWK with kid %q was not found", kid) + return nil, fmt.Errorf("missing JWK with kid %q and non-empty alg", kid) } // ValidateTokenSignature validates the signature of a token with the diff --git a/tools/auth/internal/jwk/jwk_test.go b/tools/auth/internal/jwk/jwk_test.go index d628bacc..189efcc2 100644 --- a/tools/auth/internal/jwk/jwk_test.go +++ b/tools/auth/internal/jwk/jwk_test.go @@ -168,6 +168,12 @@ func TestFetch(t *testing.T) { true, nil, }, + { + "matching kid (no alg)", + "abc", + true, + nil, + }, { "matching kid", "def",