given the func (v *Validator) refreshKeys(ctx context.Context) {
    v.lock.Lock()
    defer v.lock.Unlock()

    refreshedKeys, err := getPemKeys(v.keysLocation)
    if err != nil {
        log.WithContext(ctx).Debugf("cannot get JSONWebKey: %v, falling back to old keys", err)
        return
    }

    log.WithContext(ctx).Debugf("keys refreshed, new UTC expiration time: %s", refreshedKeys.expiresInTime.UTC())
    v.keys = refreshedKeys
} I want to have another function specifically made for the embeddedIdp. We can fetch the lkeys directly from dex provider. But we need to keep the original one as not everyone is using the embeddedIdp. Dex db has keys table.

---

make sure the verification of the keys from db is done according to the original function. e.g., expiration checks etc

---

use the same code as in dex itself

---

[Request interrupted by user for tool use]

---

just use ../dexidp folder

---

what is jwks.ExpiresInTime = time.Now().Add(1 * time.Hour)

---

how is it done in the original function?

---

create a short summary of changes for a pr. I will submit it myself

---

Verify each finding against the current code and only fix it if needed.

In `@shared/auth/jwt/validator.go` around lines 95 - 109,
NewValidatorWithKeyFetcher currently assigns whatever the keyFetcher returns,
which can leave Validator.keys nil and later cause panics at
refreshedKeys.ExpiresInTime.UTC() or v.keys.stillValid(); change the constructor
to ensure Validator.keys is always non-nil by replacing nil returns with a
default &Jwks{} when err != nil or keys == nil, log the error as before, and
return the Validator with keys set to the empty &Jwks{}; apply the same
defensive change to the other similar constructors in this file (the ones around
the other noted ranges) so all paths guarantee Validator.keys is non-nil.