How to update issued at and expiry claims on each token call using Go Oauth2 library?

Viewed 111

Using the OAuth2 Client Credentials package (here) I've requesting access tokens that expire after 60 minutes. When they expire the client just reuses the config to apply for another token (because the JWT flow response doesn't include a refresh token).

The issue I'm having is the config has had the exp and iat claims set on initial authorisation.

Claims compiled code:

claims = &jws.ClaimSet{
        Iss: Iss,
        Aud: tokenURL,
        Exp: time.Now().Add(time.Second * 45).Unix(),
        Iat: time.Now().Unix(),
        Sub: Sub,
        Prn: "",
        PrivateClaims: map[string]interface{}{
            "aud":          tokenURL,
            "jti":          val,
        },
    }

and then the client is initialised with

    privateKey, err := decryptPrivateKey(AppSettings)
    if err != nil {
        return nil, fmt.Errorf("failed to configure private key: %v", err)
    }
    claims, err := createJWTClaims(AppSettings, Type)
    if err != nil {
        return nil, fmt.Errorf("failed to create claims: %v", err)
    }
    signingHeaders := createHeader(AppSettings)

    // Assemble payload params
    payload, err := jws.Encode(signingHeaders, claims, privateKey)
    if err != nil {
        return nil, errors.Wrap(err, "Failed to encode payload")
    }

    v := url.Values{}
    v.Set("grant_type", "urn:ietf:params:oauth:grant-type:jwt-bearer")
    v.Add("assertion", payload)

    config := &clientcredentials.Config{
        ClientID:       ClientID,
        ClientSecret:   ClientSecret,
        TokenURL:       tokenURL,
        Scopes:         nil,
        EndpointParams: v,
        AuthStyle:      1,
    }

    client := config.Client(context.Background())

Is there anyway to have the values set in v update on call, or point towards a variable that gets captured on use?

Edit: To rephrase the question, is there any Go method I'm missing that would allow me to have the claim within v update on call? Or alternatively, if the only solution to this to customise the TokenSource call?

0 Answers
Related