| ▲ | er0k 3 hours ago | ||||||||||||||||||||||||||||
wow I am so surprised to hear once again how JWTs are terrible | |||||||||||||||||||||||||||||
| ▲ | fabian2k 3 hours ago | parent | next [-] | ||||||||||||||||||||||||||||
Someone not verifying the signature at all is not a mistake where you can blame the JWT spec itself. | |||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||
| ▲ | talon8635 3 hours ago | parent | prev | next [-] | ||||||||||||||||||||||||||||
Does this extend to OIDC? I’m not knowledgeable on the topic but it uses JWT right? Is it also prone to poor implementation? If you just error on alg=none does that solve it? | |||||||||||||||||||||||||||||
| ▲ | Perz1val 3 hours ago | parent | prev | next [-] | ||||||||||||||||||||||||||||
Idk if that's not too much of an oversimplification, maybe more like JWTs are an indicator/enabler of architecture level bugs? | |||||||||||||||||||||||||||||
| ▲ | skhameneh 3 hours ago | parent | prev [-] | ||||||||||||||||||||||||||||
Other commenters are suggesting you can’t blame the spec for end implementation mistakes, except that’s one of the many issues - JWT being so error-prone is a problem. I use JWT just for handling of tokens, because it’s so well supported, but I won’t use it for anything more than token storage _because_ it is so vulnerable to mistakes. The fact that mistakes are so easy to make is indicative of poor design in the spec itself. | |||||||||||||||||||||||||||||