3 ms·
Thank you for this comment, I feel very much the same way. The JWT spec isn’t wonderful and it is complex however, having spent the early part of my career wor
by davewritescode 7y ago
Thank you for this comment, I feel very much the same way. The JWT spec isn’t wonderful and it is complex however, having spent the early part of my career working with SAML, SOAP and xmldsig in highly trusted environments it’s actually a breath of fresh air. Those specs were littered with security flaws.
That said, the class of attacks that relied on the attacker modifying the header of the JWT could have been totally avoided by including the header values in the signature calculation.