3 ms·
You would think so, but even an authentication company screwed it up: https://cybercx.co.nz/blog/json-web-token-validation-bypass-in-auth0-authentication-api/
by agwa 4mo ago
You would think so, but even an authentication company screwed it up:
https://cybercx.co.nz/blog/json-web-token-validation-bypass-in-auth0-authentication-api/ https://cybercx.co.nz/blog/json-web-token-validation-bypass-...
- y2244 4mo agoWow lol
- userbinator 4mo agoClearly trying to be too general. I wrote a tiny JWT validator before that only allows a very small subset of algorithms because I wasn't expecting the JWTs it would handle to have anything else, and obviously not "none".