Hey folks,
Running into a bit of a wall with auth validation in our React frontend. We’re using the implicit grant flow for a customer-facing portal, so we’re getting the access token directly in the URL fragment. The token generation works fine, and I can see the JWT payload if I decode it locally.
The problem is verifying that the token is actually valid and hasn’t been tampered with before we let the user into the app. I know Genesys Cloud uses RS256, so I’m trying to verify the token client-side.
Here’s the rough approach I’m taking with jose:
import { jwtVerify, importSPKI } from 'jose';
const TOKEN_URL = 'https://api.mypurecloud.com/api/v2/tokens/me';
async function validateToken(token) {
const response = await fetch(TOKEN_URL, {
headers: {
'Authorization': `Bearer ${token}`
}
});
if (!response.ok) {
return null;
}
const tokenInfo = await response.json();
return tokenInfo;
}
It’s bombing out because I’m trying to verify the signature locally without the public keys. I can’t find a public JWKS endpoint in the Genesys Cloud Platform API spec to fetch the RS256 keys for local verification. I’m not sure how to reconstruct the public key properly without pulling in a heavy crypto library that doesn’t play nice with our build, or if there’s a way to get the keys at all.
Is there a cleaner way to handle this in a browser environment? Or is it better to just call a backend endpoint to validate the token instead of doing it in the React app? We want to avoid the extra latency if possible, but security is obviously important.
Any pointers appreciated.