how is the access token handled in the oidc-filter?

I think it works with both. I haven't looked at it in a while, but I believe I only used the id_token because it is not as short-lived. You should be able to use them interchangeably


I like the oidc-filter code and have a question : in response to auth code with client id/secret request, the token endpoint of openid-connect authorization server returns both access token and id_token. I see the oidc-filter code sets the id_token (also called JWT token in your description) in cookie and sets the token to the value of the authorization header for subsequence filter to verify it. I do not find any code to process the access token returned by the token endpoint of openid-connect authorization server. If it is processed in the code, could you please tell me where it is processed? if it is not processed, could you please tell me why the filter does not need to process it, such as verify or set the access token to the cookie?

