| ▲ | fabian2k 3 hours ago | |||||||||||||
Someone not verifying the signature at all is not a mistake where you can blame the JWT spec itself. | ||||||||||||||
| ▲ | meindnoch 2 hours ago | parent | next [-] | |||||||||||||
They did verify the signature, and it was correct according to the "none" algorithm. | ||||||||||||||
| ||||||||||||||
| ▲ | buckle8017 3 hours ago | parent | prev [-] | |||||||||||||
JWT is complicated. Complexity is a spec failure in security issues. It's that simple. | ||||||||||||||