Code Coverage
 
Lines
Functions and Methods
Classes and Traits
Total
n/a
0 / 0
n/a
0 / 0
CRAP
n/a
0 / 0
1<?php
2
3declare(strict_types=1);
4
5namespace LambdaTwelve\OneRecord\Auth\Jwt;
6
7/**
8 * Where the public keys of trusted issuers come from. Keys never come from
9 * the token itself (no jku, no x5u, no embedded jwk): a token can only name a
10 * key the host already trusts.
11 */
12interface KeyResolver
13{
14    /**
15     * Candidate public keys (PEM) for a token from $issuer, narrowed to $keyId
16     * when the token names one and the resolver knows it. An empty list means
17     * the issuer is not trusted.
18     *
19     * @return list<string>
20     */
21    public function publicKeys(string $issuer, ?string $keyId): array;
22}