Uploaded image for project: 'James Server'
  1. James Server
  2. JAMES-3423

WebAdmin should have it's ownJWT public key

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Closed
    • Major
    • Resolution: Done
    • None
    • 3.6.0
    • webadmin

    Description

      Today, webadmin relies on JWT configuration for the JMAP protocol.

      This brings concerns, as the tenant are distinct (users vs admins), and the token issuers are likely distinct.

      The compromission of a webmail service would today easily grant access to the webadmin APIs.

      As such it is desirable to be able to specify distinct keys for both protocols.

      In order to avoid breaking changes, if the webadmin JWT public key is unspecified, we should fallback to the JMAP one.

      Attachments

        Activity

          People

            Unassigned Unassigned
            btellier Benoit Tellier
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: