2 ms·
Various, been a while since I wrote code using them myself. Often JWT tokens come from sources other than our own and they will have passed through user agent
by Arnout 6y ago
Various, been a while since I wrote code using them myself.
Often JWT tokens come from sources other than our own and they will have passed through user agent or client land. Don't trust anything in them unless you verified them.
edit: good on that library! That's what it should do. Clearly auth0's code did not do that though, it should never have accepted any variant of 'none' in the first place.
- applecrazy 6y agoJust wanted to point out the supreme irony: Auth0 wrote that library.
- Arnout 6y agoHah. They could still improve it by only accepting a single algorithm, rather than a list. edit: though there could be some internal use cases where you want a list, but it's a tradeoff between flexibility and making it easy for people to shoot themselves in the foot.
- wongarsu 6y agoIf you don't set it it's set to a reasonable list of algorithms [0], which doesn't include "none" https://github.com/auth0/node-jsonwebtoken/blob/master/verify.js#L113 https://github.com/auth0/node-jsonwebtoken/blob/master/verif...