Skip to content

Commit 6b64ea3

Browse files
committed
explain jwks cache invalidation in the README
Signed-off-by: Julien Veyssier <julien-nc@posteo.net>
1 parent a031bf0 commit 6b64ea3

1 file changed

Lines changed: 13 additions & 0 deletions

File tree

‎README.md‎

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -114,6 +114,19 @@ To skip the confirmation, use `--force`.
114114
***Warning***: be careful with the deletion of a provider because in some setup, this invalidates access to all
115115
NextCloud accounts associated with this provider.
116116

117+
#### JWKS cache invalidation
118+
119+
A provider-specific JWKS cache is stored by user_oidc. This cache is valid for one hour.
120+
If the JWKS changed on the IdP side, you can clear this JWKS
121+
cache by editing the provider with occ. You don't have to change any value. For example, if your provider identifier is
122+
`my_identifier` and the client ID is `my_client_id`, you can run:
123+
124+
```
125+
occ user_oidc:provider my_identifier --clientid my_client_id
126+
```
127+
128+
to clear the JWKS cache of the provider `my_identifier`.
129+
117130
#### Avatar support
118131

119132
The avatar attribute on your IdP side may contain a URL pointing to an image file or directly a base64 encoded image.

0 commit comments

Comments
 (0)