Token encoded with empty string payload throw invalid token error on verify()
Nobody has claimed this yet.
Assessment
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Newbie friendliness
- 45/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Stale
- Tech stack
- javascript
- Domain
- authentication, security
Research direction
Start at verify.js around line 75 and trace how the empty payload produced by jwt.sign('', 'someKey') is parsed by jwt.verify(). Compare the two entry points against the reproduction; done when an empty payload is either verifiable as '' or rejected during signing rather than producing an unverifiable token.
Written by the indexing model from the issue text.
Description
Description
When you sign a key with an empty string as a payload, the verification throws JsonWebTokenError: invalid token. Instead, I expect it to return the empty string, ''. If this can't be accomplished, then I think it should fail to sign with some sort of invalid payload error. I wouldn't expect it to be possible to sign something that cannot be verified.
Reproduction
> jwt.sign('', 'someKey')
'eyJhbGciOiJIUzI1NiJ9..4Q39XnmJ95pIs0bJ05Gq_byy31eRYSrlmhrgKI5FHkk'
> jwt.verify('eyJhbGciOiJIUzI1NiJ9..4Q39XnmJ95pIs0bJ05Gq_byy31eRYSrlmhrgKI5FHkk', 'someKey')
Thrown:
JsonWebTokenError: invalid token
at Object.module.exports [as verify] (/home/project/node_modules/jsonwebtoken/verify.js:75:17) {
name: 'JsonWebTokenError',
message: 'invalid token'
}
Environment
jsonwebtoken: 8.5.1
node v12.13.0
- Dominant language
- JavaScript
- Stars
- 18.2k
- Forks
- 1.3k
- PR merge metrics
- No merged PRs in 30d
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from auth0/node-jsonwebtoken
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
auth0/node-jsonwebtoken#1042 · 1 comment ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
auth0/node-jsonwebtoken#1000 · 2 comments · 1 reaction ·
-
Difficulty 4/5 3-5 days Newbie friendliness 65/100
auth0/node-jsonwebtoken#1046 ·
-
Difficulty 5/5 Over a week Newbie friendliness 10/100
auth0/node-jsonwebtoken#1034 ·
-
Difficulty 3/5 1-2 days Newbie friendliness 48/100
auth0/node-jsonwebtoken#1032 ·
All issues in auth0/node-jsonwebtoken
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
antfu-collective/icones#398 ·
-
ECmail.com Open
Difficulty 1/5 Under an hour Newbie friendliness 90/100
wesbos/burner-email-providers#554 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
radiantearth/stac-browser#1023 ·
-
HMR stops working Open
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
components-web-app/docs#92 ·