IdentityServer4 custom token validation called only once

Viewed 20

I am currently working on the logic of custom token validation. I need to deactivate the token when the user's password is changed (change-password endpoint is public). I have implemented the ICustomTokenRequestValidator interface and resolved my class via DI .AddCustomTokenRequestValidator<TokenHashValidatorService>();

However, I can see the following problem, my implementation of ICustomTokenRequestValidator only works when I generate a token and during only the first request to my API. In logs I see the following information:

JWKS request from log

During first request to API request to /.well-known/openid-configuration and /.well-known/openid-configuration/jwks is sent. But when I send a second, third, etc. requests my breakpoint in TokenHashValidatorService is skipped.

Is there any way I can forcefully initiate second /.well-known/openid-configuration and /.well-known/openid-configuration/jwks requests? Or maybe I can somehow mark that "token validation needed" during the change-password flow?

I'm really stuck and out of options, I've read all the articles out there, any ideas?

0 Answers
Related