Problem
SessionConfig.jwt_algorithm accepts RS*, ES*, PS* and EdDSA (JWT_ALGORITHMS in fastapi_cachex/session/config.py). However, JWTTokenSerializer signs and verifies every token with the single secret_key string (token_serializers.py, self._secret = config.secret_key.get_secret_value()).
For an asymmetric algorithm, PyJWT needs a private key to encode and a public key to decode, so a string secret fails:
>>> jwt.encode({"a": 1}, "x" * 40, algorithm="RS256")
jwt.exceptions.InvalidKeyError: Could not parse the provided public key.
The configuration is accepted at startup, but the first create_session() fails at runtime.
Options
- Validate early: restrict
jwt_algorithm to HS256/HS384/HS512 unless a custom token_serializer is supplied. Alternatively, raise a clear configuration error when an asymmetric algorithm is combined with the built-in serializer. Rejecting values the config accepts today would be a breaking change.
- Support asymmetric keys: add
jwt_private_key / jwt_public_key settings (PEM, SecretStr for the private key). The built-in serializer would encode with the private key and decode with the public one, so services that only verify tokens can hold just the public key.
Option 1 is the minimum fix. Option 2 makes the accepted values actually work.
Current documentation
docs/JWT_CLAIMS.md (since #85) notes that only the HS algorithms work out of the box, and that asymmetric algorithms need a custom serializer.
Problem
SessionConfig.jwt_algorithmacceptsRS*,ES*,PS*andEdDSA(JWT_ALGORITHMSinfastapi_cachex/session/config.py). However,JWTTokenSerializersigns and verifies every token with the singlesecret_keystring (token_serializers.py,self._secret = config.secret_key.get_secret_value()).For an asymmetric algorithm, PyJWT needs a private key to encode and a public key to decode, so a string secret fails:
The configuration is accepted at startup, but the first
create_session()fails at runtime.Options
jwt_algorithmtoHS256/HS384/HS512unless a customtoken_serializeris supplied. Alternatively, raise a clear configuration error when an asymmetric algorithm is combined with the built-in serializer. Rejecting values the config accepts today would be a breaking change.jwt_private_key/jwt_public_keysettings (PEM,SecretStrfor the private key). The built-in serializer would encode with the private key and decode with the public one, so services that only verify tokens can hold just the public key.Option 1 is the minimum fix. Option 2 makes the accepted values actually work.
Current documentation
docs/JWT_CLAIMS.md(since #85) notes that only the HS algorithms work out of the box, and that asymmetric algorithms need a custom serializer.