checkFreshness
function checkFreshness( auth, maxAuthAge, now?): number;Defined in: src/token-identity.ts:425
Return the caller’s auth_time, or refuse if it is missing or stale.
A credential with no verifiable auth_time cannot mint. That single rule is
what stops a grant being used to mint another grant: a grant is not an
IdP-issued token, so it carries no auth_time, so the lineage cannot escape
the identity provider. It also makes subprocess and unix transports fail
closed for free – there is no authenticated principal there at all.
A static bearer proves a machine holds a secret, never that a human just authenticated, so it is refused here too.
Warning: auth_time is an OIDC claim meaning when this session began,
which can be arbitrarily old while still present and cryptographically valid.
Requiring it is not the same as requiring a recent login: the deployment must
send max_age (or an appropriate acr) at the authorize endpoint for this
guard to mean what it says.
maxAuthAge and now are seconds, matching the claim’s own units.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
auth |
AuthContext |
maxAuthAge |
number |
now? |
number |
Returns
Section titled “Returns”number
