Remix.run Logo
▲ fabian2k 3 hours ago

Someone not verifying the signature at all is not a mistake where you can blame the JWT spec itself.

▲meindnoch 2 hours ago | parent | next [-]

They did verify the signature, and it was correct according to the "none" algorithm.

▲fabian2k 2 hours ago | parent | next [-]

Argh, I missed that it actually uses the "none" algorithm. Yeah, the existence of that option is extremely dumb and it shouldn't be possible to use that. I misread the post and thought it was a regular JWT, but they simply didn't validate it.

▲alex_suzuki 2 hours ago | parent | prev [-]

“Works as designed.”

▲buckle8017 3 hours ago | parent | prev [-]

JWT is complicated.

Complexity is a spec failure in security issues.

It's that simple.