← 문제 라이브러리
Security Advanced SECURITY-066 · 20 min

JWKS cache on the API gateway stays stale after OIDC signing key rotation

The identity provider is healthy and publishes the new key, but valid tokens still fail because the gateway never refreshed its cached trust material in time.

Pro
시나리오

The identity provider is healthy and publishes the new key, but valid tokens …

구독하면 이어서 볼 수 있어요

이 문제의 전체 시나리오와 점검 체크리스트, 복구 순서, 모범 풀이는 Pro 구독에서 열립니다.

구독 안내 보기