验证标准 ID 令牌声明
学习验证 OpenID Connect ID 令牌中 iss、aud、exp、iat 和 nonce 声明的必需步骤。
验证标准 ID 令牌声明 是 CoddyKit 上的免费 OAuth2 & OpenID Connect Deep Dive 课时。 这是第 4 节课,共 4 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 OAuth2 & OpenID Connect Deep Dive 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 OAuth2 & OpenID Connect Deep Dive 课程共包含 4 节课。
本课时的部分内容尚未翻译,以英文显示。
Signature Is Not Enough
Verifying an ID token's signature proves it came from the provider, but you must also validate its claims to ensure it was meant for you, right now, and is still valid. A valid signature on a token meant for another app is still dangerous.
Validate iss (Issuer)
The iss claim must exactly equal the issuer identifier of your trusted provider, as published in its discovery document. Reject anything else.
if (claims.iss !== 'https://op.example.com') reject();Validate aud (Audience)
The aud claim must contain your client_id. If aud is an array with multiple values, an azp (authorized party) claim must be present and equal your client_id.
const auds = Array.isArray(claims.aud) ? claims.aud : [claims.aud];
if (!auds.includes(MY_CLIENT_ID)) reject();Validate exp (Expiration)
The exp claim is a Unix timestamp. The current time must be before exp. Reject expired tokens; allow a small clock skew (a few minutes) at most.
const now = Math.floor(Date.now() / 1000);
if (now >= claims.exp) reject('expired');Validate iat (Issued At)
The iat claim says when the token was issued. You can reject tokens that are unreasonably old, and use iat to enforce freshness policies.
if (now - claims.iat > MAX_AGE_SECONDS) reject('too old');Validate nonce
If you sent a nonce in the authentication request, the token's nonce must equal the value you stored. This blocks replay.
if (claims.nonce !== session.nonce) reject('nonce mismatch');Check azp When Present
The azp (authorized party) claim identifies which client the token was issued to when there are multiple audiences. If present, it must match your client_id.
auth_time and max_age
If you requested max_age or auth_time is essential, verify the auth_time claim shows the user authenticated recently enough; otherwise force re-authentication.
Order of Operations
A safe sequence:
- Decode and verify the signature (correct alg + key).
- Validate iss, aud/azp.
- Validate exp, iat (and auth_time if needed).
- Validate nonce.
Only after all pass do you trust the identity.
A Combined Check
Bringing the claim validations together:
function validateClaims(c, cfg, now) {
if (c.iss !== cfg.issuer) throw 'bad iss';
const auds = [].concat(c.aud);
if (!auds.includes(cfg.clientId)) throw 'bad aud';
if (now >= c.exp) throw 'expired';
if (c.nonce !== cfg.nonce) throw 'bad nonce';
return true;
}Use a Vetted Library
Hand-rolling JWT validation invites subtle bugs (alg confusion, skew handling). Prefer a well-maintained OIDC/JWT library and only configure the policy; let it enforce signature and claim checks.
Quick Check
Check your claim-validation knowledge.
Recap
Validating ID token claims goes beyond the signature:
issmust match the trusted issuer;audmust include your client_id.exp/iatenforce validity and freshness (allow small skew).nonceblocks replay; checkazpwith multiple audiences.- Prefer a vetted library over hand-rolled checks.
用 AI 导师学习 OAuth2 & OpenID Connect Deep Dive — 免费
在浏览器中编写并运行真实代码,获得全天候 AI 导师的即时帮助,并在网页或应用中继续学习。
- 课程
- 12
- 课程
- 48
常见问题解答
「验证标准 ID 令牌声明」课时是免费的吗?
是的 — 「验证标准 ID 令牌声明」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 OAuth2 & OpenID Connect Deep Dive 课程的其余内容,请升级到 CoddyKit PRO。 OAuth2 & OpenID Connect Deep Dive 课程共包含 4 节课。
「验证标准 ID 令牌声明」这节课中我会学到什么?
学习验证 OpenID Connect ID 令牌中 iss、aud、exp、iat 和 nonce 声明的必需步骤。 你通过在浏览器中直接运行的动手代码来练习 OAuth2 & OpenID Connect Deep Dive,全天候 AI 导师会在你学习这节课的过程中回答你的问题。
学习 OAuth2 & OpenID Connect Deep Dive 需要有经验吗?
无需任何先前经验。CoddyKit 上的 OAuth2 & OpenID Connect Deep Dive 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 4 节课,共 4 节。
「验证标准 ID 令牌声明」课时需要多长时间?
大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。
我能在这节 OAuth2 & OpenID Connect Deep Dive 课中编写并运行代码吗?
能。每节 OAuth2 & OpenID Connect Deep Dive 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。
此课程中的所有课时
- ID 令牌结构与签名
- JWS 与 JWK 集
- 令牌撤销与内省
- 验证标准 ID 令牌声明