Skip to content
CCPEDIAby Unity Nodes
Discussions/App Development/Verification of ApplicationID in JWTForum ↗

Verification of ApplicationID in JWT

App Development3 posts512 views6 likesLast activity Apr 2020
PI
Piyush_BediOP
Apr 2020

Does the AuthService bundled with the SDK validate the ApplicationID in the JWT against the ApplicationID supplied in the LedgerAPI Command?

The Authorizer seems to ignore it: https://github.com/digital-asset/daml/blob/878429e3bf07b09e727224d5dc423444d071a95b/ledger/ledger-api-auth/src/main/scala/com/digitalasset/ledger/api/auth/Authorizer.scala#L29

ST
stefanobaghino-da
Apr 2020

You are absolutely right, this is a bug. Thanks to @Robert_Autenrieth for looking into this.

I’m opening a ticket to track this.

ST
stefanobaghino-da
Apr 2020

Tracked by Authorization ignores the application identifier in the token · Issue #5683 · digital-asset/daml · GitHub.

Thanks for raising this.

← Back to Discussions