Use an ID token or access token at userinfo endpoint?

Viewed 1240

I have a client API, that is a confidential client. When I authenticate with an open id provider, I am redirected to my callback with an authorization code, which is immediately exchanged to receive a refresh token, an access token, and an ID token.

Now, I create a session cookie that has a uuid for the authenticated user. When the user makes a request, do I...

  1. Use my access token to call the providers userinfo endpoint to get the user info.
  2. Read the validated ID token to get the users info.

When it comes to using the refresh token I see 2 options:

  1. After reading a valid ID token or access token during a request, use the refresh token to get a new access or ID token to store at a new uuid, which is returned to the user with an updated cookie. While requiring the user to sign in more, this means the users session becomes invalid after inactivity on their part equaling the lifetime of the access or ID token. This is potentially more secure.
  2. Use the ID token or access token until valid and then refresh to get a new one. If the refresh never expires, the user will never have to sign in again even if inactive for a long period of time ( unless cookie expiration is low ) Potentially less secure.

Thoughts?

2 Answers

In short, you only use an authentication token to access userinfo_endpoint uri.

OpenID Connect allows the use of a "Discovery document," a JSON document found at a well-known location containing key-value pairs which provide details about the OpenID Connect provider's configuration, including the URIs of the authorization, token, revocation, userinfo, and public-keys endpoints.

You can research each applications unique discovery page uri from their docs for example here is Google

You make a get request to the discovery document uri and from this document you find the userinfo_endpoint uri.

Example response from microsoft

GET https://login.microsoftonline.com/organizations/v2.0/.well-known/openid-configuration
{
  "authorization_endpoint": "https://login.microsoftonline.com/{tenant}/oauth2/v2.0/authorize",
  "token_endpoint": "https://login.microsoftonline.com/{tenant}/oauth2/v2.0/token",
  "token_endpoint_auth_methods_supported": [
    "client_secret_post",
    "private_key_jwt"
  ],
  "jwks_uri": "https://login.microsoftonline.com/{tenant}/discovery/v2.0/keys",
  "userinfo_endpoint": "https://graph.microsoft.com/oidc/userinfo",
  "subject_types_supported": [
      "pairwise"
  ],
  ...

}

Google's discovery doc uri

GET https://accounts.google.com/.well-known/openid-configuration

Get an Authorization token. For example pull up Network -> Fetch/ XHR now look around and try to find a request header with the key 'authorization'. Copy 'Bearer {the id}' and put in the header of a get request like the picture shown below.

GET or POST /oidc/userinfo HTTP/1.1
Host: graph.microsoft.com
Authorization: Bearer eyJ0eXAiOiJKV1QiLCJub25jZSI6Il…

Microsoft Example Postman Request enter image description here

Related