Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Extending JWT claims validation to support other claims

Open
#5,418 4 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
45/100
Issue type
Feature
Clarity
Mostly clear
Activity status
Stale
Tech stack
erlang

Research direction

Start with src/jwtf/src/jwtf.erl, especially the claim checks referenced at line 45, and review how required_claims is parsed. The change is complete when a configuration such as required_claims = exp, {aud, "my-application"} validates aud for existence and the supplied value, while supporting other provided claims without unknown_checks.

Written by the indexing model from the issue text.

Description

beginner-friendly enhancement patches-welcome

Based on source, I understand only limited number of JWT claims can be validated. Trying to validate other claims result in error unknown_checks.
I would like to ask for introducing validation any provided claim.

In my case, I use an SSO of a huge Organisation, where many users can define their own applications/clients (signed with same SSO key). Without validating aud, anyone could create another application with roles that my CouchDB instance accepts.

Desired Behaviour

When provided a config like below, the claim aud should be verified: both if it exists and if it matched provided my-application value.

required_claims = exp, {aud, "my-application"}

I believe it's worth allowing such a validation for any custom claim (only to check existence and value matching, if provided).

Possible Solution

I believe the source should not limit the check only to claims specified in line 45. There could be a function providing a "general" claim check, no matter what it is exactly.

Dominant language
Erlang
Stars
7k
Forks
1.1k
Avg merge
1d 23m
Merged PRs (30d)
30

Getting set up

Open in Codespaces

Starts the project's dev container in your browser, under your own GitHub account.

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from apache/couchdb

All issues in apache/couchdb

Similar issues

More Security issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.