diff --git a/OpenIDConnectClient.php5 b/OpenIDConnectClient.php5 index 4a2e7484..fc639ad6 100644 --- a/OpenIDConnectClient.php5 +++ b/OpenIDConnectClient.php5 @@ -308,7 +308,7 @@ class OpenIDConnectClient */ private function verifyJWTclaims($claims) { - return (($claims->iss == self::getProviderURL()) + return (rtrim($claims->iss,'/') == rtrim(self::getProviderURL(),'/')) && (($claims->aud == $this->clientID) || (in_array($this->clientID, $claims->aud))) && ($claims->nonce == $_SESSION['openid_connect_nonce']));