4 ms·
I think the main concept you are missing is called HMAC, which is a cryptography thing. If you don't know this, I will recommend this explanation [1]. The clie
by jfroma 12y ago
I think the main concept you are missing is called HMAC, which is a cryptography thing. If you don't know this, I will recommend this explanation [1].
The client can send something wrong? Yes, as long as the client can digital sign what is sending with the secret you expect.
JWTs can be signed with a symmetric key or an asymmetric key, the vulnerability mentioned in this post is when the server-side expect a token digitally signed with an asymmetric key but an unauthorized client uses the public key to create a signature as if the key where symmetric. The issue in this case is when the server is blindly accepting any algorithm.
[1]: http://security.stackexchange.com/a/20301/9332 http://security.stackexchange.com/a/20301/9332