test.gyeo.me

JWT Validation

Worker는 JWT를 발급하고 JWKS만 노출합니다. 검증은 Cloudflare API JWT Validation rule 담당. 각 시나리오가 엣지에서 차단되는지 관찰.

구성
Issuer (iss)https://test.gyeo.me/jwt-validation
Audience (aud)test-gyeo-me-lab
JWKS endpoint/.well-known/jwks.json
Protected endpointGET /jwt-validation/api/secure (워커 무방비)
검증 위치대시보드 Security → Security rules → API JWT validation rules
결과 해석

✓ 정상 토큰

올바른 issuer/audience + 5분 유효한 정상 ES256 토큰. 엣지가 통과시켜야 함.

⚠ 만료된 토큰

exp가 3분 전 (Cloudflare의 60초 clock drift 허용을 넘김). 엣지 rule이 exp 자동 검증.

🛑 서명 변조

정상 토큰 발급 후 서명 마지막 글자만 변조. 엣지 rule이 서명 검증으로 차단.

이 데모가 보여주는 것