| ▲ | meindnoch 2 hours ago | |
They did verify the signature, and it was correct according to the "none" algorithm. | ||
| ▲ | fabian2k 2 hours ago | parent | next [-] | |
Argh, I missed that it actually uses the "none" algorithm. Yeah, the existence of that option is extremely dumb and it shouldn't be possible to use that. I misread the post and thought it was a regular JWT, but they simply didn't validate it. | ||
| ▲ | alex_suzuki 2 hours ago | parent | prev [-] | |
“Works as designed.” | ||