Skip to content

Commit

Permalink
Update JWT documentation to recommend only using jwt_header or audit …
Browse files Browse the repository at this point in the history
…logging not both (#5914)

* readd auth token doc

Signed-off-by: Stephen Crawford <[email protected]>

* Fix vale

Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Co-authored-by: kolchfa-aws <[email protected]>
Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Co-authored-by: kolchfa-aws <[email protected]>
Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Co-authored-by: kolchfa-aws <[email protected]>
Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Co-authored-by: kolchfa-aws <[email protected]>
Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Co-authored-by: kolchfa-aws <[email protected]>
Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Co-authored-by: kolchfa-aws <[email protected]>
Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Co-authored-by: kolchfa-aws <[email protected]>
Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Co-authored-by: kolchfa-aws <[email protected]>
Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Co-authored-by: kolchfa-aws <[email protected]>
Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Co-authored-by: kolchfa-aws <[email protected]>
Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Co-authored-by: kolchfa-aws <[email protected]>
Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Co-authored-by: kolchfa-aws <[email protected]>
Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Co-authored-by: kolchfa-aws <[email protected]>
Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Co-authored-by: kolchfa-aws <[email protected]>
Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Co-authored-by: kolchfa-aws <[email protected]>
Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Co-authored-by: kolchfa-aws <[email protected]>
Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Co-authored-by: kolchfa-aws <[email protected]>
Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Co-authored-by: kolchfa-aws <[email protected]>
Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Co-authored-by: kolchfa-aws <[email protected]>
Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Co-authored-by: kolchfa-aws <[email protected]>
Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Co-authored-by: kolchfa-aws <[email protected]>
Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Signed-off-by: Stephen Crawford <[email protected]>

* Apply suggestions from code review

Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Signed-off-by: Stephen Crawford <[email protected]>

* Apply suggestions from code review

Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Signed-off-by: Stephen Crawford <[email protected]>

* Fix embedded command

Signed-off-by: Stephen Crawford <[email protected]>

* Blank lines after headings

Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Co-authored-by: Melissa Vagi <[email protected]>
Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Co-authored-by: Melissa Vagi <[email protected]>
Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Co-authored-by: Melissa Vagi <[email protected]>
Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Co-authored-by: Melissa Vagi <[email protected]>
Signed-off-by: Stephen Crawford <[email protected]>

* change

Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Co-authored-by: Melissa Vagi <[email protected]>
Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Co-authored-by: Melissa Vagi <[email protected]>
Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Co-authored-by: Melissa Vagi <[email protected]>
Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Co-authored-by: Melissa Vagi <[email protected]>
Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Co-authored-by: Melissa Vagi <[email protected]>
Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Co-authored-by: Melissa Vagi <[email protected]>
Signed-off-by: Stephen Crawford <[email protected]>

* Apply suggestions from code review

Co-authored-by: Melissa Vagi <[email protected]>
Signed-off-by: Stephen Crawford <[email protected]>

* Style guidelines

Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Signed-off-by: Stephen Crawford <[email protected]>

* Apply suggestions from code review

Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Co-authored-by: kolchfa-aws <[email protected]>
Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Co-authored-by: kolchfa-aws <[email protected]>
Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Co-authored-by: kolchfa-aws <[email protected]>
Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/access-control/authentication-tokens.md

Co-authored-by: kolchfa-aws <[email protected]>
Signed-off-by: Stephen Crawford <[email protected]>

* warn about audit logging of custom headers

Signed-off-by: Stephen Crawford <[email protected]>

* Update _security/authentication-backends/jwt.md

Co-authored-by: Naarcha-AWS <[email protected]>
Signed-off-by: Stephen Crawford <[email protected]>

---------

Signed-off-by: Stephen Crawford <[email protected]>
Signed-off-by: Stephen Crawford <[email protected]>
Co-authored-by: kolchfa-aws <[email protected]>
Co-authored-by: Melissa Vagi <[email protected]>
Co-authored-by: Naarcha-AWS <[email protected]>
(cherry picked from commit 7d8a6a3)
  • Loading branch information
stephen-crawford authored and Naarcha-AWS committed Dec 21, 2023
1 parent b64372e commit f5024c9
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion _security/authentication-backends/jwt.md
Original file line number Diff line number Diff line change
Expand Up @@ -116,7 +116,7 @@ The following table lists the configuration parameters.
Name | Description
:--- | :---
`signing_key` | The signing key to use when verifying the token. If you use a symmetric key algorithm, it is the base64-encoded shared secret. If you use an asymmetric algorithm, it contains the public key.
`jwt_header` | The HTTP header in which the token is transmitted. This is typically the `Authorization` header with the `Bearer` schema: `Authorization: Bearer <token>`. Default is `Authorization`.
`jwt_header` | The HTTP header in which the token is transmitted. This is typically the `Authorization` header with the `Bearer` schema,`Authorization: Bearer <token>`. Default is `Authorization`. Replacing this field with a value other than `Authorization` prevents the audit log from properly redacting the JWT header from audit messages. It is recommended that users only use `Authorization` when using JWTs with audit logging.
`jwt_url_parameter` | If the token is not transmitted in the HTTP header but rather as an URL parameter, define the name of the parameter here.
`subject_key` | The key in the JSON payload that stores the username. If not set, the [subject](https://tools.ietf.org/html/rfc7519#section-4.1.2) registered claim is used.
`roles_key` | The key in the JSON payload that stores the user's roles. The value of this key must be a comma-separated list of roles.
Expand Down

0 comments on commit f5024c9

Please sign in to comment.