You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Currently, JWT.decode always expects to have the algorithms provided by the client.
When using JWKs this information can be redundant since supported algorithms can be resolved from the provided keys.
RSA and HMAC keys can have the alg property specifying the algorithm
EC keys this information can be resolved from the crv property
This kind of resolve will be triggered only if the client is not explicitly specifying the algorithms (the current behavior).
Do you see any security issues resolving the algorithm from the JWK?
The text was updated successfully, but these errors were encountered:
Currently,
JWT.decode
always expects to have the algorithms provided by the client.When using JWKs this information can be redundant since supported algorithms can be resolved from the provided keys.
alg
property specifying the algorithmcrv
propertyThis kind of resolve will be triggered only if the client is not explicitly specifying the algorithms (the current behavior).
Do you see any security issues resolving the algorithm from the JWK?
The text was updated successfully, but these errors were encountered: