JWKS cache never expires — key rotation requires restart #58
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
fetch_or_get_jwks caches JWKS forever. When Keycloak rotates signing keys, all new tokens are rejected until the process restarts. Fix: Add TTL (5 min) and force-refresh fallback when kid is not found.