-
Type:
Improvement
-
Resolution: Unresolved
-
Priority:
Major - P3
-
None
-
Affects Version/s: None
-
Component/s: None
-
None
-
Server Security
-
None
-
None
-
None
-
None
-
None
-
None
-
None
Today, the crypto API module contains a considerable amount of "crypto" code that is specific to the access_control ** module, in particular regarding OIDC auth (JWS, JWKS, JWKS fetcher, etc.), but must be made public to use across modules.
Modify the files/directory/module to reduce this coupling and reduce the scope of public-facing crypto APIs.