JWT Validation
Worker는 JWT를 발급하고 JWKS만 노출합니다. 검증은 Cloudflare API JWT Validation rule 담당. 각 시나리오가 엣지에서 차단되는지 관찰.
구성
| Issuer (iss) | https://test.gyeo.me/jwt-validation |
| Audience (aud) | test-gyeo-me-lab |
| JWKS endpoint | /.well-known/jwks.json |
| Protected endpoint | GET /jwt-validation/api/secure (워커 무방비) |
| 검증 위치 | 대시보드 Security → Security rules → API JWT validation rules |
결과 해석
200 reachedWorker: true→ 엣지 rule이 이 토큰을 통과시킴 (워커까지 도달)4xx+ Cloudflare block page HTML → 엣지 rule이 이 토큰을 차단4xx+ custom JSON (예:blocked-by-edge-jwt-rule) → rule action의 Custom JSON response로 차단
✓ 정상 토큰
올바른 issuer/audience + 5분 유효한 정상 ES256 토큰. 엣지가 통과시켜야 함.
⚠ 만료된 토큰
exp가 3분 전 (Cloudflare의 60초 clock drift 허용을 넘김). 엣지 rule이 exp 자동 검증.
🛑 서명 변조
정상 토큰 발급 후 서명 마지막 글자만 변조. 엣지 rule이 서명 검증으로 차단.
이 데모가 보여주는 것
- Worker는 IdP 역할만 — 고정 keypair로 토큰 발급 + JWKS 서빙
/api/secure는 무방비. 검증은 대시보드 rule 담당- Cloudflare JWT Validation rule은 기본으로 서명 + 만료 + nbf만 자동 검증. iss/aud 검증은 Custom Rule에서
lookup_json_string(http.request.jwt.claims[...])으로 추가 구현 - 서명 변조 / 만료 → rule ON 시 엣지 차단 예상. iss/aud 불일치 → 별도 Custom Rule 없으면 워커까지 도달