TsgcHTTP_JWT_Server component.
The TsgcHTTP_JWT_Server component allows you to decode and validate JWT tokens received in WebSocket Handshake when using WebSocket protocol or as HTTP Header when using HTTP protocol.
You can configure the following properties in the JWTOptions property of the component:
If the Signature is validated using a Public Key (RS and ES algorithms), set the value in the PublicKey property of the Algorithm.
If the Signature is validated using a Secret (HS algorithms), set the value in the Secret property of the Algorithm.
To validate JWT tokens, just attach a TsgcHTTP_JWT_Server instance to Authentication.JWT.JWT property of the WebSocket/HTTP Server.
oServer := TsgcWebSocketHTTPServer.Create(nil);
oServer.Port := 80;
oJWT := TsgcHTTP_JWT_Server.Create(nil);
oJWT.JWTOptions.Algorithms.RS.PublicKey.Text := 'public key here';
oServer.Authorization.Enabled := True;
oServer.Authorization.JWT.JWT := oJWT;
oServer.Active := True;
Once the signature has been verified, the server validates the registered claims of the Payload. The exp, nbf and iat claims are checked, earlier versions only verified the signature, so an expired token was accepted. A claim which is not present in the Payload is not asserted by the issuer and is not validated.
The checks are configured in the JWTOptions.Validations property:
Expiration: rejects the token when the exp claim is in the past. Enabled by default, set Validations.Expiration := False to disable the expiry check.
NotBefore: rejects the token when the nbf claim is in the future. Enabled by default.
Issued: rejects the token when the iat claim is in the future. Enabled by default.
Leeway: seconds of clock skew allowed when the exp, nbf and iat claims are compared with the current time. The default is 60 seconds, set it to zero to compare the claims with no allowance.