diff --git a/authn/authenticate.go b/authn/authenticate.go index 81a87ed5c..7611ff7d8 100644 --- a/authn/authenticate.go +++ b/authn/authenticate.go @@ -190,8 +190,21 @@ func (a *Auth) Authenticate(access, refresh string) (*UserInfo, error) { claims := *token.Claims.(*jwt.MapClaims) // expiry check - if exp, ok := claims["exp"].(string); ok { - if expiry, err := strconv.ParseInt(exp, 10, 64); err != nil || expiry < time.Now().UTC().Unix() { + if exp, ok := claims["exp"]; ok { + var expiry int64 + switch v := exp.(type) { + case string: + expiry, err = strconv.ParseInt(v, 10, 64) + if err != nil { + return nil, fmt.Errorf("parsing exp string: %v", err) + } + case float64: + expiry = int64(v) + case int64: + expiry = v + } + + if expiry < time.Now().UTC().Unix() { access, refresh, err = a.refreshToken(access, refresh) if err != nil { return nil, fmt.Errorf("token is expired: %w", err) diff --git a/authn/authenticate_internal_test.go b/authn/authenticate_internal_test.go index caae2350e..664754891 100644 --- a/authn/authenticate_internal_test.go +++ b/authn/authenticate_internal_test.go @@ -267,7 +267,7 @@ func TestAuthenticate(t *testing.T) { claims["oid"] = test.uid claims["name"] = test.uname if test.exp != 0 { - claims["exp"] = strconv.Itoa(int(test.exp)) + claims["exp"] = float64(test.exp) } token, err = tkn.SignedString(a.SecretKey()) if err != nil { @@ -298,7 +298,7 @@ func TestAuthenticate(t *testing.T) { claims := tkn.Claims.(jwt.MapClaims) claims["oid"] = test.uid claims["name"] = test.uname - expiry := strconv.Itoa(int(time.Now().Add(2 * time.Hour).Unix())) + expiry := float64(time.Now().Add(2 * time.Hour).Unix()) claims["exp"] = expiry fresh, err := tkn.SignedString(a.SecretKey()) if err != nil { @@ -306,7 +306,7 @@ func TestAuthenticate(t *testing.T) { } a.groupsCache[fresh] = cachedGroups{time.Now(), test.groups} - fmt.Fprintf(w, `{"access_token": "`+fresh+`", "refresh_token": "blah", "token_type": "bearer", "expires": `+expiry+` }`) + fmt.Fprintf(w, `{"access_token": "`+fresh+`", "refresh_token": "blah", "token_type": "bearer", "expires": `+strconv.FormatFloat(expiry, 'f', 0, 64)+` }`) })) defer srv.Close() a.oAuthConfig.Endpoint.TokenURL = srv.URL @@ -571,7 +571,7 @@ func TestHandlers(t *testing.T) { claims["name"] = "user name" expiresIn := 2 * time.Hour exp := time.Now().Add(expiresIn) - expiry := strconv.Itoa(int(exp.Unix())) + expiry := float64(exp.Unix()) claims["exp"] = expiry fresh, err := tkn.SignedString(a.SecretKey()) if err != nil {