JWT Authorization

JWT Authorization

The JWT Authorization component provides JSON Web Token validation and authorization management within the middleware tree.

Features

  • Token validation and verification
  • Role-based access control
  • Token refresh handling
  • Claim validation
  • Secure secret management

XAML Configuration

<JWTAuthorizationComponent Name="JWTAuth" 
                          Path=":jwt"
                          Secret="{Binding JWTSecret}"
                          Issuer="{Binding TokenIssuer}"
                          Audience="{Binding TokenAudience}"
                          onAuthorize="handleAuth"
                          onError="handleError">
    
    <!-- Protected components -->
    <ChildComponent />
</JWTAuthorizationComponent>

Implementation

class JWTAuthorizationComponent extends CoreElement {
    constructor() {
        super();
        this.properties.set("secret", "");
        this.properties.set("issuer", "");
        this.properties.set("audience", "");
    }

    async handleEvent(event: MiddlewareEvent): Promise<void> {
        if (event.type === "authorize") {
            const token = event.data.token;
            try {
                const decoded = jwt.verify(token, this.properties.get("secret"), {
                    issuer: this.properties.get("issuer"),
                    audience: this.properties.get("audience")
                });
                
                event.data.user = decoded;
                await this.routeEvent(new MiddlewareEvent("authorized", {
                    user: decoded
                }));
            } catch (error) {
                await this.routeEvent(new MiddlewareEvent("unauthorized", {
                    error: error.message
                }));
            }
        }
    }
}

WPF Integration

In WPF, the component provides:

  • Token validation testing
  • Claim inspection
  • Authorization flow visualization
  • Error monitoring

Best Practices

  1. Security

    • Use environment variables for secrets
    • Implement token expiration
    • Validate all claims
  2. Error Handling

    • Handle token expiration gracefully
    • Provide clear error messages
    • Implement refresh logic
  3. Authorization Flow

    • Check permissions early
    • Cache validation results
    • Use appropriate token lifetime