Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Arnout
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
Arnout
6y ago
Hah. They could still improve it by only accepting a single algorithm, rather than a list. edit: though there could be some internal use cases where you want a list, but it's a tradeoff between flexibility and making it easy for people
2.
▲
by
Arnout
6y ago
Various, been a while since I wrote code using them myself. Often JWT tokens come from sources other than our own and they will have passed through user agent or client land. Don't trust anything in them unless you verified them. edit:
3.
▲
by
Arnout
6y ago
I've encountered issues like this in various systems using JWT at this point. The real problem is that developers blacklist the algorithms they don't want. Instead, the verification code should explicitly whitelist which algorithm
4.
▲
by
Arnout
7y ago
Pretty much the case every single time. It's how cycling infrastructure finally got taken seriously in the Netherlands too - https://www.youtube.com/watch?v=XuBdf9jYj7o
5.
▲
by
Arnout
11y ago
I last tried the bootcamp/vmware setup with a Vista partition; it really confused the activation system and kept de-activating.
6.
▲
by
Arnout
12y ago
Don't trust the data before you verified it is indeed the common problem here. You have to be careful with JWK in a similar way: the public key can be specified a as a URL via the x5u parameter, you have to make sure you only trust key
7.
▲
by
Arnout
14y ago
Now annoyingly the ELB on AWS just bounces PATCH requests with a 405 Method Not Allowed. Our services are affected by this and I noticed there is a bug open over at Heroku regarding the same issue. It's something Amazon don't document thoug