An encoded JWT.
Modulejose-jwt-0.10.0Haskell2010
Jose.Jwt
High-level JWT encoding and decoding.
See the Jose.Jws and Jose.Jwe modules for specific JWS and JWE examples.
Example usage with a key stored as a JWK:
import Jose.Jweimport Jose.Jwaimport Jose.Jwkimport Data.ByteStringimport Data.Aeson (decodeStrict)let jsonJwk = "{\"kty\":\"RSA\", \"kid\":\"mykey\", \"n\":\"ofgWCuLjybRlzo0tZWJjNiuSfb4p4fAkd_wWJcyQoTbji9k0l8W26mPddxHmfHQp-Vaw-4qPCJrcS2mJPMEzP1Pt0Bm4d4QlL-yRT-SFd2lZS-pCgNMsD1W_YpRPEwOWvG6b32690r2jZ47soMZo9wGzjb_7OMg0LOL-bSf63kpaSHSXndS5z5rexMdbBYUsLA9e-KXBdQOS-UTo7WTBEMa2R2CapHg665xsmtdVMTBQY4uDZlxvb3qCo5ZwKh9kG4LT6_I5IhlJH7aGhyxXFvUK-DWNmoudF8NAco9_h9iaGNj8q2ethFkMLs91kzk2PAcDTW9gb54h4FRWyuXpoQ\", \"e\":\"AQAB\", \"d\":\"Eq5xpGnNCivDflJsRQBXHx1hdR1k6Ulwe2JZD50LpXyWPEAeP88vLNO97IjlA7_GQ5sLKMgvfTeXZx9SE-7YwVol2NXOoAJe46sui395IW_GO-pWJ1O0BkTGoVEn2bKVRUCgu-GjBVaYLU6f3l9kJfFNS3E0QbVdxzubSu3Mkqzjkn439X0M_V51gfpRLI9JYanrC4D4qAdGcopV_0ZHHzQlBjudU2QvXt4ehNYTCBr6XCLQUShb1juUO1ZdiYoFaFQT5Tw8bGUl_x_jTj3ccPDVZFD9pIuhLhBOneufuBiB4cS98l2SR_RQyGWSeWjnczT0QU91p1DhOVRuOopznQ\"}" :: ByteStringlet Just jwk = decodeStrict jsonJwk :: Maybe JwkRight (Jwt jwtEncoded) <- encode [jwk] (JwsEncoding RS256) (Claims "public claims")Right jwtDecoded <- Jose.Jwt.decode [jwk] (Just (JwsEncoding RS256)) jwtEncodedjwtDecodedJws (JwsHeader {jwsAlg = RS256, jwsTyp = Nothing, jwsCty = Nothing, jwsKid = Just (KeyId "mykey")},"public claims")
- 13 types
- 7 values
- Packagejose-jwt-0.10.0
- Exports20
- LanguageHaskell2010
- LicenceBSD-3-Clause
- SourceJwt.hs
The header and claims of a decoded JWS.
A decoded JWT which can be either a JWE or a JWS, or an unsecured JWT.
Instances2Eq, Show
Eq JwtContentDefined in jose-jwt-0.10.0 · Jose.TypesShow JwtContentDefined in jose-jwt-0.10.0 · Jose.Types
The header and claims of a decoded JWE.
Header content for a JWS.
Instances6Eq, Show, Generic, FromJSON, ToJSON, Rep
Eq JwsHeaderDefined in jose-jwt-0.10.0 · Jose.TypesShow JwsHeaderDefined in jose-jwt-0.10.0 · Jose.TypesGeneric JwsHeaderDefined in jose-jwt-0.10.0 · Jose.TypesFromJSON JwsHeaderDefined in jose-jwt-0.10.0 · Jose.TypesToJSON JwsHeaderDefined in jose-jwt-0.10.0 · Jose.Typestype Rep JwsHeader = D1 ('MetaDataDefined in jose-jwt-0.10.0 · Jose.Types"JwsHeader"
"Jose.Types"
"jose-jwt-0.10.0-JrXGHRx8z295E7SmwJlDez"
'False) (C1 ('MetaCons"JwsHeader"
'PrefixI 'True) ((S1 ('MetaSel ('Just"jwsAlg"
) 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedLazy) (Rec0 JwsAlg) :*: S1 ('MetaSel ('Just"jwsTyp"
) 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedLazy) (Rec0 (Maybe Text))) :*: (S1 ('MetaSel ('Just"jwsCty"
) 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedLazy) (Rec0 (Maybe Text)) :*: S1 ('MetaSel ('Just"jwsKid"
) 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedLazy) (Rec0 (Maybe KeyId)))))
Header content for a JWE.
Instances6Eq, Show, Generic, FromJSON, ToJSON, Rep
Eq JweHeaderDefined in jose-jwt-0.10.0 · Jose.TypesShow JweHeaderDefined in jose-jwt-0.10.0 · Jose.TypesGeneric JweHeaderDefined in jose-jwt-0.10.0 · Jose.TypesFromJSON JweHeaderDefined in jose-jwt-0.10.0 · Jose.TypesToJSON JweHeaderDefined in jose-jwt-0.10.0 · Jose.Typestype Rep JweHeader = D1 ('MetaDataDefined in jose-jwt-0.10.0 · Jose.Types"JweHeader"
"Jose.Types"
"jose-jwt-0.10.0-JrXGHRx8z295E7SmwJlDez"
'False) (C1 ('MetaCons"JweHeader"
'PrefixI 'True) ((S1 ('MetaSel ('Just"jweAlg"
) 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedLazy) (Rec0 JweAlg) :*: (S1 ('MetaSel ('Just"jweEnc"
) 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedLazy) (Rec0 Enc) :*: S1 ('MetaSel ('Just"jweTyp"
) 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedLazy) (Rec0 (Maybe Text)))) :*: (S1 ('MetaSel ('Just"jweCty"
) 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedLazy) (Rec0 (Maybe Text)) :*: (S1 ('MetaSel ('Just"jweZip"
) 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedLazy) (Rec0 (Maybe Text)) :*: S1 ('MetaSel ('Just"jweKid"
) 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedLazy) (Rec0 (Maybe KeyId))))))
Decoding errors.
Constructors
KeyError TextNo suitable key or wrong key type
BadAlgorithm TextThe supplied algorithm is invalid
BadDots IntWrong number of "." characters in the JWT
BadHeader TextHeader couldn't be decoded or contains bad data
BadClaimsClaims part couldn't be decoded or contains bad data
BadSignatureSignature is invalid
BadCryptoA cryptographic operation failed
Base64Error StringA base64 decoding error
The payload to be encoded in a JWT.
Constructors
Constructors
Registered claims defined in section 4 of the JWT spec.
Instances5Show, Generic, FromJSON, ToJSON, Rep
Show JwtClaimsDefined in jose-jwt-0.10.0 · Jose.TypesGeneric JwtClaimsDefined in jose-jwt-0.10.0 · Jose.TypesFromJSON JwtClaimsDefined in jose-jwt-0.10.0 · Jose.TypesToJSON JwtClaimsDefined in jose-jwt-0.10.0 · Jose.Typestype Rep JwtClaims = D1 ('MetaDataDefined in jose-jwt-0.10.0 · Jose.Types"JwtClaims"
"Jose.Types"
"jose-jwt-0.10.0-JrXGHRx8z295E7SmwJlDez"
'False) (C1 ('MetaCons"JwtClaims"
'PrefixI 'True) ((S1 ('MetaSel ('Just"jwtIss"
) 'NoSourceUnpackedness 'SourceStrict 'DecidedStrict) (Rec0 (Maybe Text)) :*: (S1 ('MetaSel ('Just"jwtSub"
) 'NoSourceUnpackedness 'SourceStrict 'DecidedStrict) (Rec0 (Maybe Text)) :*: S1 ('MetaSel ('Just"jwtAud"
) 'NoSourceUnpackedness 'SourceStrict 'DecidedStrict) (Rec0 (Maybe [Text])))) :*: ((S1 ('MetaSel ('Just"jwtExp"
) 'NoSourceUnpackedness 'SourceStrict 'DecidedStrict) (Rec0 (Maybe IntDate)) :*: S1 ('MetaSel ('Just"jwtNbf"
) 'NoSourceUnpackedness 'SourceStrict 'DecidedStrict) (Rec0 (Maybe IntDate))) :*: (S1 ('MetaSel ('Just"jwtIat"
) 'NoSourceUnpackedness 'SourceStrict 'DecidedStrict) (Rec0 (Maybe IntDate)) :*: S1 ('MetaSel ('Just"jwtJti"
) 'NoSourceUnpackedness 'SourceStrict 'DecidedStrict) (Rec0 (Maybe Text))))))
Defines the encoding information for a JWT.
Used for both encoding new JWTs and validating existing ones.
Constructors
Instances2Eq, Show
Eq JwtEncodingDefined in jose-jwt-0.10.0 · Jose.TypesShow JwtEncodingDefined in jose-jwt-0.10.0 · Jose.Types
Instances6Eq, Num, Ord, Show, FromJSON, ToJSON
Eq IntDateDefined in jose-jwt-0.10.0 · Jose.TypesNum IntDateDefined in jose-jwt-0.10.0 · Jose.TypesOrd IntDateDefined in jose-jwt-0.10.0 · Jose.TypesShow IntDateDefined in jose-jwt-0.10.0 · Jose.TypesFromJSON IntDateDefined in jose-jwt-0.10.0 · Jose.TypesToJSON IntDateDefined in jose-jwt-0.10.0 · Jose.Types
encode :: MonadRandom m=> [Jwk]The key or keys. At least one must be consistent with the chosen algorithm
-> JwtEncodingThe encoding algorithm(s) used to encode the payload
-> PayloadThe payload (claims)
-> m (Either JwtError Jwt)The encoded JWT, if successful
Use the supplied JWKs to create a JWT. The list of keys will be searched to locate one which is consistent with the chosen encoding algorithms.
decode :: MonadRandom m=> [Jwk]The keys to use for decoding
-> Maybe JwtEncodingThe expected encoding information
-> ByteStringThe encoded JWT
-> m (Either JwtError JwtContent)The decoded JWT payload, if successful
Uses the supplied keys to decode a JWT.
Locates a matching key by header kid value where possible
or by suitable key type for the encoding algorithm.
The algorithm(s) used can optionally be supplied for validation
by setting the JwtEncoding parameter, in which case an error will
be returned if they don't match. If you expect the tokens to use
a particular algorithm, then you should set this parameter.
For unsecured tokens (with algorithm "none"), the expected algorithm
must be set to Just (JwsEncoding None) or an error will be returned.
Convenience function to return the claims contained in a JWS.
This is needed in situations such as client assertion authentication,
https://tools.ietf.org/html/rfc7523, where the contents of the JWT,
such as the sub claim, may be required in order to work out
which key should be used to verify the token.
Obviously this should not be used by itself to decode a token since no integrity checking is done and the contents may be forged.