italia/spid-cie-oidc-django

Resolve endpoint returns non-compliant trust_chain

Closed this issue · 1 comments

Expected Behavior

Resolve endpoint responds with a trust chain that conforms to the specification.

Current Behavior

Resolve endpoint responds with a partially nested trust chain, not conforming to the specification. The order of the returned JWTs is also wrong, i.e., the first two JWTs are entity configurations of the leaf and the TA, while the third JWT is a subordinate statement issued by the TA about the leaf.

Possible Solution

I guess the bug can be found in line 280

Steps to Reproduce

  • Use the resolve endpoint of the trust anchor to create a trust chain from the cie-provider to the trust anchor itself:
    curl "https://trust-anchor.testbed.oidcfed.incubator.geant.org/resolve/?sub=https://cie-provider.testbed.oidcfed.incubator.geant.org/oidc/op/&anchor=https://trust-anchor.testbed.oidcfed.incubator.geant.org/"
  • Response:
JWT
eyJhbGciOiJSUzI1NiIsImtpZCI6IkJYdmZybG5oQU11SFIwN2FqVW1BY0JSUWNTem13MGNfUkFnSm5wUy05V1EifQ..SNLtamZr6Ypmyv3sqZqKaJ5Y_rLN-2cQlmH0PMbu5_M6AvOE-MXXwODeQYG3vPEHnjYMkJpItzk2iNWo2dYwnNQHdqPpuKxLVbCFS2pOtKiH4wEOOaLVNJYFoRebv3rwU7PF3z7jG8S3V2QfXnXC4Jdrmn2UO7gfhaNO7Fyu5eXh_MZ_z7oBw_vi_8kfUew-fuAOzqPAzvQ_rNcTQ6c1pUcfArsgrAYRBFDK--tw_Mk41k27pSgfBLspMNnvvkXuLMr0u8_R1S0OO3DZk9J3C5J37z3_HYXfxG12OYlo72ey7MPLJyDl5lvwZEbgg4Wfym7hikuYI9N5q52O9oPJvQ%
  • Extract the trust chain from the JWT
full trust_chain
"trust_chain": [
    "eyJhbGciOiJSUzI1NiIsImtpZCI6IlpoU29hT2VkVk9zQnc2bTJ2Y2x3U1dpcXFuR2VPU3RULWdVY2xvdF82N3ciLCJ0eXAiOiJlbnRpdHktc3RhdGVtZW50K2p3dCJ9.eyJleHAiOjE2NTA5MDE2NDgsImlhdCI6MTY1MDcyODg0OCwiaXNzIjoiaHR0cDovLzEyNy4wLjAuMTo4MDAyL29pZGMvb3AvIiwic3ViIjoiaHR0cDovLzEyNy4wLjAuMTo4MDAyL29pZGMvb3AvIiwiandrcyI6eyJrZXlzIjpbeyJrdHkiOiJSU0EiLCJlIjoiQVFBQiIsIm4iOiJ0ZzNhRTlmZDZsdFh6TnJpbV80Q0dLWVdmQzNucWNfdHY0WGphdzQ3M0NjcmZpcUR6ZVRLSGZSZmJ2YnFiMUR3bUk0ZnZDT2k1MUVWY21LTG5UaHpYeW5BVXB5VXZzd3ZMOF91emdEV08xUlNtQkcxTDBSRS1Da0tpaDRrZVhoMWt1OWhOczFfVi04MmRLNW9MT1ItVkpMbmhaQ3FUaFI0SEg2VHFMampXcnJYZnNIVlJ2YXVKaWxYNkZ4R2I1SkZvYzI3Vnh4ZEgyYzZQMlNIQzl3dUI4dG5mRzdPU3JTRDFnMmg3bFRYYklmbTc4YTBvcDY3ZF9qdXB6a29Lb0NUbXprUjJ6dndUVlZEZDk5dmtETFkyV1htYjhoSXdHNmRRWlhZbGtocUFZS3pUdVRaMHRqVmgwT3JxZkR4WXRMSDN3UXp6YUpPUmV3WllxTHlCMDlQOHciLCJraWQiOiJaaFNvYU9lZFZPc0J3Nm0ydmNsd1NXaXFxbkdlT1N0VC1nVWNsb3RfNjd3In1dfSwibWV0YWRhdGEiOnsib3BlbmlkX3Byb3ZpZGVyIjp7ImF1dGhvcml6YXRpb25fZW5kcG9pbnQiOiJodHRwOi8vMTI3LjAuMC4xOjgwMDIvb2lkYy9vcC9hdXRob3JpemF0aW9uIiwicmV2b2NhdGlvbl9lbmRwb2ludCI6Imh0dHA6Ly8xMjcuMC4wLjE6ODAwMi9vaWRjL29wL3Jldm9jYXRpb24vIiwiaWRfdG9rZW5fZW5jcnlwdGlvbl9hbGdfdmFsdWVzX3N1cHBvcnRlZCI6WyJSU0EtT0FFUCJdLCJpZF90b2tlbl9lbmNyeXB0aW9uX2VuY192YWx1ZXNfc3VwcG9ydGVkIjpbIkExMjhDQkMtSFMyNTYiXSwib3BfbmFtZSI6IkFnZW56aWEgcGVyIGxcdTIwMTlJdGFsaWEgRGlnaXRhbGUiLCJvcF91cmkiOiJodHRwczovL3d3dy5hZ2lkLmdvdi5pdCIsInRva2VuX2VuZHBvaW50IjoiaHR0cDovLzEyNy4wLjAuMTo4MDAyL29pZGMvb3AvdG9rZW4vIiwidXNlcmluZm9fZW5kcG9pbnQiOiJodHRwOi8vMTI3LjAuMC4xOjgwMDIvb2lkYy9vcC91c2VyaW5mby8iLCJpbnRyb3NwZWN0aW9uX2VuZHBvaW50IjoiaHR0cDovLzEyNy4wLjAuMTo4MDAyL29pZGMvb3AvaW50cm9zcGVjdGlvbi8iLCJjbGFpbXNfcGFyYW1ldGVyX3N1cHBvcnRlZCI6dHJ1ZSwiY29udGFjdHMiOlsib3BzQGh0dHBzOi8vaWRwLml0Il0sImNvZGVfY2hhbGxlbmdlX21ldGhvZHNfc3VwcG9ydGVkIjpbIlMyNTYiXSwiY2xpZW50X3JlZ2lzdHJhdGlvbl90eXBlc19zdXBwb3J0ZWQiOlsiYXV0b21hdGljIl0sInJlcXVlc3RfYXV0aGVudGljYXRpb25fbWV0aG9kc19zdXBwb3J0ZWQiOnsiYXIiOlsicmVxdWVzdF9vYmplY3QiXX0sImFjcl92YWx1ZXNfc3VwcG9ydGVkIjpbImh0dHBzOi8vd3d3LnNwaWQuZ292Lml0L1NwaWRMMSIsImh0dHBzOi8vd3d3LnNwaWQuZ292Lml0L1NwaWRMMiIsImh0dHBzOi8vd3d3LnNwaWQuZ292Lml0L1NwaWRMMyJdLCJjbGFpbXNfc3VwcG9ydGVkIjpbImdpdmVuX25hbWUiLCJmYW1pbHlfbmFtZSIsImJpcnRoZGF0ZSIsImdlbmRlciIsInBob25lX251bWJlciIsImh0dHBzOi8vYXR0cmlidXRlcy5laWQuZ292Lml0L2Zpc2NhbF9udW1iZXIiLCJwaG9uZV9udW1iZXJfdmVyaWZpZWQiLCJlbWFpbCIsImFkZHJlc3MiLCJkb2N1bWVudF9kZXRhaWxzIiwiaHR0cHM6Ly9hdHRyaWJ1dGVzLmVpZC5nb3YuaXQvcGh5c2ljYWxfcGhvbmVfbnVtYmVyIl0sImdyYW50X3R5cGVzX3N1cHBvcnRlZCI6WyJhdXRob3JpemF0aW9uX2NvZGUiLCJyZWZyZXNoX3Rva2VuIl0sImlkX3Rva2VuX3NpZ25pbmdfYWxnX3ZhbHVlc19zdXBwb3J0ZWQiOlsiUlMyNTYiLCJFUzI1NiJdLCJpc3N1ZXIiOiJodHRwOi8vMTI3LjAuMC4xOjgwMDIvb2lkYy9vcC8iLCJqd2tzIjp7ImtleXMiOlt7Imt0eSI6IlJTQSIsInVzZSI6InNpZyIsImUiOiJBUUFCIiwibiI6InJKb1NZdjFzdHdsYk0xMXRSOVNZR0lKdXpxbEplMmJ2Mk4zNW9QUmJ3Vl9lcGpOV3ZHRzJacUVqNTNZRk1DOEFNWk5GaHVMYV9MTndyMWtMVkUtalhRZTh4amlMaGU3RGdNZjFPblN6cTl5QUVYVm8xOUJQQndrZ0plMmpwOUhJZ01fbmZiSXNVYlNTa0ZBTTJDS3ZHYjBCazJHdnZxWFoxMlAtZnBiVnlBOWhJUXI2ck5UcW5DR3gyLXY0b1ZpR0c0dV8zaVR3N0QxWnZMV21ybVpPYUtuREFxRzNNSlNkUS0yZ2dRLUFpYWhnNDhzaTlDOURfSmduQlY5dEoyZUNTNThaQzZrVkc1c2Z0RWxRVmRINmUyNm16NDY0VFpqNVFnQ3daQ1RzQVFmSXZCb1hTZENLeHBudnNGZnJhano0cTlCaVhBcnl4SU9sNWZMbUNGVk5odyIsImtpZCI6IlBkMk45LVRael9BV1MzR0ZDa29ZZFJhWFhsczhZUGh4X2RfRXo3SndqUUkifV19LCJzY29wZXNfc3VwcG9ydGVkIjpbIm9wZW5pZCIsIm9mZmxpbmVfYWNjZXNzIl0sImxvZ29fdXJpIjoiaHR0cDovLzEyNy4wLjAuMTo4MDAyL3N0YXRpYy9pbWFnZXMvbG9nby1jaWUucG5nIiwib3JnYW5pemF0aW9uX25hbWUiOiJTUElEIE9JREMgaWRlbnRpdHkgcHJvdmlkZXIiLCJvcF9wb2xpY3lfdXJpIjoiaHR0cDovLzEyNy4wLjAuMTo4MDAyL29pZGMvb3AvZW4vd2Vic2l0ZS9sZWdhbC1pbmZvcm1hdGlvbi8iLCJyZXF1ZXN0X3BhcmFtZXRlcl9zdXBwb3J0ZWQiOnRydWUsInJlcXVlc3RfdXJpX3BhcmFtZXRlcl9zdXBwb3J0ZWQiOnRydWUsInJlcXVpcmVfcmVxdWVzdF91cmlfcmVnaXN0cmF0aW9uIjp0cnVlLCJyZXNwb25zZV90eXBlc19zdXBwb3J0ZWQiOlsiY29kZSJdLCJyZXNwb25zZV9tb2Rlc19zdXBwb3J0ZWQiOlsicXVlcnkiLCJmb3JtX3Bvc3QiXSwic3ViamVjdF90eXBlc19zdXBwb3J0ZWQiOlsicGFpcndpc2UiLCJwdWJsaWMiXSwidG9rZW5fZW5kcG9pbnRfYXV0aF9tZXRob2RzX3N1cHBvcnRlZCI6WyJwcml2YXRlX2tleV9qd3QiXSwidG9rZW5fZW5kcG9pbnRfYXV0aF9zaWduaW5nX2FsZ192YWx1ZXNfc3VwcG9ydGVkIjpbIlJTMjU2IiwiUlMzODQiLCJSUzUxMiIsIkVTMjU2IiwiRVMzODQiLCJFUzUxMiJdLCJ1c2VyaW5mb19lbmNyeXB0aW9uX2FsZ192YWx1ZXNfc3VwcG9ydGVkIjpbIlJTQS1PQUVQIiwiUlNBLU9BRVAtMjU2IiwiRUNESC1FUyIsIkVDREgtRVMrQTEyOEtXIiwiRUNESC1FUytBMTkyS1ciLCJFQ0RILUVTK0EyNTZLVyJdLCJ1c2VyaW5mb19lbmNyeXB0aW9uX2VuY192YWx1ZXNfc3VwcG9ydGVkIjpbIkExMjhDQkMtSFMyNTYiLCJBMTkyQ0JDLUhTMzg0IiwiQTI1NkNCQy1IUzUxMiIsIkExMjhHQ00iLCJBMTkyR0NNIiwiQTI1NkdDTSJdLCJ1c2VyaW5mb19zaWduaW5nX2FsZ192YWx1ZXNfc3VwcG9ydGVkIjpbIlJTMjU2IiwiUlMzODQiLCJSUzUxMiIsIkVTMjU2IiwiRVMzODQiLCJFUzUxMiJdLCJyZXF1ZXN0X29iamVjdF9lbmNyeXB0aW9uX2FsZ192YWx1ZXNfc3VwcG9ydGVkIjpbIlJTQS1PQUVQIiwiUlNBLU9BRVAtMjU2IiwiRUNESC1FUyIsIkVDREgtRVMrQTEyOEtXIiwiRUNESC1FUytBMTkyS1ciLCJFQ0RILUVTK0EyNTZLVyJdLCJyZXF1ZXN0X29iamVjdF9lbmNyeXB0aW9uX2VuY192YWx1ZXNfc3VwcG9ydGVkIjpbIkExMjhDQkMtSFMyNTYiLCJBMTkyQ0JDLUhTMzg0IiwiQTI1NkNCQy1IUzUxMiIsIkExMjhHQ00iLCJBMTkyR0NNIiwiQTI1NkdDTSJdLCJyZXF1ZXN0X29iamVjdF9zaWduaW5nX2FsZ192YWx1ZXNfc3VwcG9ydGVkIjpbIlJTMjU2IiwiUlMzODQiLCJSUzUxMiIsIkVTMjU2IiwiRVMzODQiLCJFUzUxMiJdfX0sImF1dGhvcml0eV9oaW50cyI6WyJodHRwOi8vMTI3LjAuMC4xOjgwMDAvIl19.WnWh9OkfAzb6YCo-yrnV9-7K_I3fucMVxNuw7tr7V43nVvgGJd4BqBSqc8Q0nKgzLcnNtnhf3MRiJ-hVkUL6vhaxt6jsXWvJupRQDf7f6-AgeNPvsHNvlrjoUkVNvTDS3jPUwXtnW7k7xQLEpdoxFW2ggbeG0zLfyyBypEGW3IZa1fDxlnEWvHH7Kctu55OBT_PC514HlKHWBYrBLYMODDoV-PCfOochOroSj3nM1WlDg50OoPXdjRUvM4eRxOmjEOF4kdXK2AKXY8wGMhJere07XnFk7TjdfLMNUdGaDR0aiPYoBkshq7Vhpy8pXt-JdN7RKKjjK-WAFLdEwASDtQ",
    "eyJhbGciOiJSUzI1NiIsImtpZCI6IkJYdmZybG5oQU11SFIwN2FqVW1BY0JSUWNTem13MGNfUkFnSm5wUy05V1EiLCJ0eXAiOiJlbnRpdHktc3RhdGVtZW50K2p3dCJ9.eyJleHAiOjE2NTA3MzA4MjgsImlhdCI6MTY1MDcyODg0OCwiaXNzIjoiaHR0cDovLzEyNy4wLjAuMTo4MDAwLyIsInN1YiI6Imh0dHA6Ly8xMjcuMC4wLjE6ODAwMC8iLCJqd2tzIjp7ImtleXMiOlt7Imt0eSI6IlJTQSIsImUiOiJBUUFCIiwibiI6Im84SW9sUmpabGt6Y3QtNDhyaHJWbFRuWVUxcGtNYlZKRC1EVTA1b01TOVJWR3JzRnlwZzk4bS1LdzRINHFOUHlRVngyT1FPUmkteFNoZ2s3SFUtZ0tfMnBWZ3VZa3YwNkZhakxfZWRFQXFxc3F0Xzc0UWYyV0xSQzVwZkpHX3o5T1B6WThKR3lrLXozU2JlSE5fQlhLSThHWTVFNFdVMlNzdG1ROWZ5TDRDeHRSZmpVaWE4bGltVENfM01PcFQzemk1bnIwM2pmYmpwbmpnYTUxcVh1cnhubHpjM2FfeGprNVJBQXBLeFV2TndoSjI3NU0wQ21COTlEalB3RjZCTHZVZ0pxZ3lDcFVPbjM2TE9oSTRGcXVWcWhxaGl3S2xNbWlNZTN5eTB5TlE3RlhCV3hqemhleGJweWMzVnU3ekZJSFBBY0M0VXlJUWhjM3dhRWoydmlYdyIsImtpZCI6IkJYdmZybG5oQU11SFIwN2FqVW1BY0JSUWNTem13MGNfUkFnSm5wUy05V1EifV19LCJtZXRhZGF0YSI6eyJmZWRlcmF0aW9uX2VudGl0eSI6eyJjb250YWN0cyI6WyJvcHNAbG9jYWxob3N0Il0sImZlZGVyYXRpb25fZmV0Y2hfZW5kcG9pbnQiOiJodHRwOi8vMTI3LjAuMC4xOjgwMDAvZmV0Y2gvIiwiZmVkZXJhdGlvbl9yZXNvbHZlX2VuZHBvaW50IjoiaHR0cDovLzEyNy4wLjAuMTo4MDAwL3Jlc29sdmUvIiwiZmVkZXJhdGlvbl9zdGF0dXNfZW5kcG9pbnQiOiJodHRwOi8vMTI3LjAuMC4xOjgwMDAvdHJ1c3RfbWFya19zdGF0dXMvIiwiaG9tZXBhZ2VfdXJpIjoiaHR0cDovLzEyNy4wLjAuMTo4MDAwIiwibmFtZSI6ImV4YW1wbGUgVEEiLCJmZWRlcmF0aW9uX2xpc3RfZW5kcG9pbnQiOiJodHRwOi8vMTI3LjAuMC4xOjgwMDAvbGlzdC8ifX0sInRydXN0X21hcmtzX2lzc3VlcnMiOnsiaHR0cHM6Ly93d3cuc3BpZC5nb3YuaXQvY2VydGlmaWNhdGlvbi9ycC9wdWJsaWMiOlsiaHR0cHM6Ly9yZWdpc3RyeS5zcGlkLmFnaWQuZ292Lml0IiwiaHR0cHM6Ly9wdWJsaWMuaW50ZXJtZWRpYXJ5LnNwaWQuaXQiXSwiaHR0cHM6Ly93d3cuc3BpZC5nb3YuaXQvY2VydGlmaWNhdGlvbi9ycC9wcml2YXRlIjpbImh0dHBzOi8vcmVnaXN0cnkuc3BpZC5hZ2lkLmdvdi5pdCIsImh0dHBzOi8vcHJpdmF0ZS5vdGhlci5pbnRlcm1lZGlhcnkuaXQiXSwiaHR0cHM6Ly9zZ2QuYWEuaXQvb25ib2FyZGluZyI6WyJodHRwczovL3NnZC5hYS5pdCJdfSwiY29uc3RyYWludHMiOnsibWF4X3BhdGhfbGVuZ3RoIjoxfX0.LA69BlKROnjaOO3qBQuvfFpFOzEEPCnyvU0gDW4j_20tUqvdJMLfdEAtxwoBg7xBXYhImHnG5mGLvL1zvZWM8LWAzpPq4HeXSjsa0b05o819Ix4k3wImiH6JKdzHr2A4P3aaup5mI_0XrN2VqYh8TSIxkJTXCjYmgGa2g11ulv2wwyzVjVIMiq5KQ6EFgJ3CVXGDOfgl5VO_WeaNsp7-ujLbD-6ULOexPI8NQvyth7ObsnD0jkKUQ_fDrNkJfh4lk7ffMT309D5RyWXkdlzNYlo_d4buv9A5AnsUyMCNBQJppDFAYGCwc40TC7pW4hbANSZQCbY6C4fBUp3ED_88uA",
    [
      "eyJhbGciOiJSUzI1NiIsImtpZCI6IkJYdmZybG5oQU11SFIwN2FqVW1BY0JSUWNTem13MGNfUkFnSm5wUy05V1EiLCJ0eXAiOiJlbnRpdHktc3RhdGVtZW50K2p3dCJ9.eyJleHAiOjE2NTA5MDE2NDgsImlhdCI6MTY1MDcyODg0OCwiaXNzIjoiaHR0cDovLzEyNy4wLjAuMTo4MDAwLyIsInN1YiI6Imh0dHA6Ly8xMjcuMC4wLjE6ODAwMi9vaWRjL29wLyIsImp3a3MiOnsia2V5cyI6W3sia3R5IjoiUlNBIiwibiI6InRnM2FFOWZkNmx0WHpOcmltXzRDR0tZV2ZDM25xY190djRYamF3NDczQ2NyZmlxRHplVEtIZlJmYnZicWIxRHdtSTRmdkNPaTUxRVZjbUtMblRoelh5bkFVcHlVdnN3dkw4X3V6Z0RXTzFSU21CRzFMMFJFLUNrS2loNGtlWGgxa3U5aE5zMV9WLTgyZEs1b0xPUi1WSkxuaFpDcVRoUjRISDZUcUxqaldyclhmc0hWUnZhdUppbFg2RnhHYjVKRm9jMjdWeHhkSDJjNlAyU0hDOXd1Qjh0bmZHN09TclNEMWcyaDdsVFhiSWZtNzhhMG9wNjdkX2p1cHprb0tvQ1RtemtSMnp2d1RWVkRkOTl2a0RMWTJXWG1iOGhJd0c2ZFFaWFlsa2hxQVlLelR1VFowdGpWaDBPcnFmRHhZdExIM3dRenphSk9SZXdaWXFMeUIwOVA4dyIsImUiOiJBUUFCIiwia2lkIjoiWmhTb2FPZWRWT3NCdzZtMnZjbHdTV2lxcW5HZU9TdFQtZ1VjbG90XzY3dyJ9XX0sIm1ldGFkYXRhX3BvbGljeSI6eyJvcGVuaWRfcHJvdmlkZXIiOnsic3ViamVjdF90eXBlc19zdXBwb3J0ZWQiOnsidmFsdWUiOlsicGFpcndpc2UiXX0sImlkX3Rva2VuX3NpZ25pbmdfYWxnX3ZhbHVlc19zdXBwb3J0ZWQiOnsic3Vic2V0X29mIjpbIlJTMjU2IiwiUlMzODQiLCJSUzUxMiIsIkVTMjU2IiwiRVMzODQiLCJFUzUxMiJdfSwidXNlcmluZm9fc2lnbmluZ19hbGdfdmFsdWVzX3N1cHBvcnRlZCI6eyJzdWJzZXRfb2YiOlsiUlMyNTYiLCJSUzM4NCIsIlJTNTEyIiwiRVMyNTYiLCJFUzM4NCIsIkVTNTEyIl19LCJ0b2tlbl9lbmRwb2ludF9hdXRoX21ldGhvZHNfc3VwcG9ydGVkIjp7InZhbHVlIjpbInByaXZhdGVfa2V5X2p3dCJdfSwidXNlcmluZm9fZW5jcnlwdGlvbl9hbGdfdmFsdWVzX3N1cHBvcnRlZCI6eyJzdWJzZXRfb2YiOlsiUlNBLU9BRVAiLCJSU0EtT0FFUC0yNTYiLCJFQ0RILUVTIiwiRUNESC1FUytBMTI4S1ciLCJFQ0RILUVTK0ExOTJLVyIsIkVDREgtRVMrQTI1NktXIl19LCJ1c2VyaW5mb19lbmNyeXB0aW9uX2VuY192YWx1ZXNfc3VwcG9ydGVkIjp7InN1YnNldF9vZiI6WyJBMTI4Q0JDLUhTMjU2IiwiQTE5MkNCQy1IUzM4NCIsIkEyNTZDQkMtSFM1MTIiLCJBMTI4R0NNIiwiQTE5MkdDTSIsIkEyNTZHQ00iXX0sInJlcXVlc3Rfb2JqZWN0X2VuY3J5cHRpb25fYWxnX3ZhbHVlc19zdXBwb3J0ZWQiOnsic3Vic2V0X29mIjpbIlJTQS1PQUVQIiwiUlNBLU9BRVAtMjU2IiwiRUNESC1FUyIsIkVDREgtRVMrQTEyOEtXIiwiRUNESC1FUytBMTkyS1ciLCJFQ0RILUVTK0EyNTZLVyJdfSwicmVxdWVzdF9vYmplY3RfZW5jcnlwdGlvbl9lbmNfdmFsdWVzX3N1cHBvcnRlZCI6eyJzdWJzZXRfb2YiOlsiQTEyOENCQy1IUzI1NiIsIkExOTJDQkMtSFMzODQiLCJBMjU2Q0JDLUhTNTEyIiwiQTEyOEdDTSIsIkExOTJHQ00iLCJBMjU2R0NNIl19LCJyZXF1ZXN0X29iamVjdF9zaWduaW5nX2FsZ192YWx1ZXNfc3VwcG9ydGVkIjp7InN1YnNldF9vZiI6WyJSUzI1NiIsIlJTMzg0IiwiUlM1MTIiLCJFUzI1NiIsIkVTMzg0IiwiRVM1MTIiXX19fSwidHJ1c3RfbWFya3MiOlt7ImlkIjoiaHR0cHM6Ly93d3cuc3BpZC5nb3YuaXQvb3BlbmlkLWZlZGVyYXRpb24vYWdyZWVtZW50L29wLXB1YmxpYy8iLCJ0cnVzdF9tYXJrIjoiZXlKaGJHY2lPaUpTVXpJMU5pSXNJbXRwWkNJNklrSllkbVp5Ykc1b1FVMTFTRkl3TjJGcVZXMUJZMEpTVVdOVGVtMTNNR05mVWtGblNtNXdVeTA1VjFFaUxDSjBlWEFpT2lKMGNuVnpkQzF0WVhKcksycDNkQ0o5LmV5SnBjM01pT2lKb2RIUndPaTh2TVRJM0xqQXVNQzR4T2pnd01EQXZJaXdpYzNWaUlqb2lhSFIwY0Rvdkx6RXlOeTR3TGpBdU1UbzRNREF5TDI5cFpHTXZiM0F2SWl3aWFXRjBJam94TmpVd056STRPRFE0TENKcFpDSTZJbWgwZEhCek9pOHZkM2QzTG5Od2FXUXVaMjkyTG1sMEwyTmxjblJwWm1sallYUnBiMjR2YjNBaUxDSnRZWEpySWpvaWFIUjBjSE02THk5M2QzY3VZV2RwWkM1bmIzWXVhWFF2ZEdobGJXVnpMMk4xYzNSdmJTOWhaMmxrTDJ4dloyOHVjM1puSWl3aWNtVm1Jam9pYUhSMGNITTZMeTlrYjJOekxtbDBZV3hwWVM1cGRDOXBkR0ZzYVdFdmMzQnBaQzl6Y0dsa0xYSmxaMjlzWlMxMFpXTnVhV05vWlMxdmFXUmpMMmwwTDNOMFlXSnBiR1V2YVc1a1pYZ3VhSFJ0YkNKOS5iQ3VlWmJDeUxMR1JSRUNUVS1QaTctdGtnSW43NGdvZHU5bW16YlVjRW5ER2xZUmpabHJLOUlXakdsb0Z1UUpOeW1RbmRXdnlFRHpISUlISVhwYUpxUTRxd3FyN2hqbVphSEMybXJFYlVBcEQ5TUU3MnJveFdvWUw0MjNJWnprWkU0QjBsMHhBemNvSWl0S0l2WmI5ZWxEaEVneUptWWdhV0ZWM0U0N2NFNHoxRGxPZWNIanA4dXR4ZEhhd0h6Tjc0bk9GNzktRFBlNnd0T1FuckprVUs0d1Bja3J3WmwtaFpsNURJbDJYUDFBMzBPRnBqUGZyMFhaXzFDU2p5TTBST196NnE1NDhXS3J2Ry1KbXBEaVl3NHJZN0Q5RkRiSEFsSlFNTC1STDdNTk1WZVRua0swNUVfWHNkTjZHRUU5TGZmcTFKRjk1SzJsTHBPWTRRQTNBcGcifV19.BtyhU0RYjVKig081cbTtN7cpCLJP6sQ9V0GTMdkoWu3D5fR8zUtdbxOK6f726k_at-6ftMQtetv85F0-u7TQG9aZqdRXmZsMsQi9HtUeGhPrfjUFYqEIctocFBhnHOiyh8sQiXRFOklRPHlui1IVa47XFmM4T7Z8tPzmPFUCucxDDkpMnEA5rdOxOfiM1cCqYJi7XVopwYJXPvMqiOqFB8QB0ESKaIOHMskvAU-208rnwxCjWS_dglmUBRdSuGuLpHUw8pjt7Z2T0oN646nwRkLMLB3oWMhaOD3pFsshpyjg2pL5LTTSvFm8wJEejvwz-guG7L283ODswMAe9y5HHQ"
    ]
  ]
}
  • Trust chain is a list with three entries: two JWTs, and a list containing another JWT.
"trust_chain": [
    "eyJhbGciOiJSUzI1NiIsImtpZC...",
    "eyJhbGciOiJSUzI1NiIsImtpZCI6Ik...",
    [
      "eyJhbGciOiJSUzI1NiIsImtpZCI6Ik..."
    ]
  ]
}

Good catch, it seems a stupid regression

I have fixed it here 8746747 and I also have added a check in the unit test related to the trust chain discovery with intermediate

I made a new release with this bugfix, thank you for the issue @tobiaspc