Tools, FAQ, Tutorials:
Validate Azure AD v1 id_token
How to validate the id_token value received from Azure AD v1.0 authentication response?
✍: FYIcenter.com
As you can see from the previous tutorials, you can easily decode the
"id_token" value received from Azure AD authentication response using a
simple PHP script.
After decoding, you can get all information about the end user from the body component, and trust it without any validation.
But, since the "id_token" is included in the authentication response delivered over the public Internet, you should not trust it and perform a number validation steps:
1. Data structure validation.
2. Data attributes validation.
3. Timestamp attributes validation. This will prevent someone to repost the authentication response to your server script at a later time.
4. "nonce" protection and validation. This will prevent someone to repost the authentication response again immediately.
5. Signature validation. This is to ensure the entire authentication response message has not been modified by someone else. See next tutorial on how to perform "id_token" signature validation.
⇒ Validate Azure AD v1 id_token Signature
2021-05-16, ∼2086🔥, 0💬
Popular Posts:
How to add request query string Parameters to my Azure API operation 2017 version to make it more us...
How to use the "send-one-way-request" Policy statement to call an extra web service for an Azure API...
How To Pass Arrays By References? in PHP? Like normal variables, you can pass an array by reference ...
How to add an API to an API product for internal testing on the Publisher Portal of an Azure API Man...
How to use the urllib.request.Request object to build more complex HTTP request? The urllib.request....