Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

allowInsecureKeySizes flag not present among TS types.

Open
#969 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
45/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Stale
Tech stack
node.js, typescript

Research direction

Start at the SignOptions declaration shown in the issue and compare it with the sign() options accepted by the package. Update the declaration so allowInsecureKeySizes is represented, then verify the reproduction no longer produces TS2769.

Written by the indexing model from the issue text.

Description

Description

I updated from version 8 to 9, and since my RSA keys were not long enough I got the error: "secretOrPrivateKey has a minimum key size of 2048 bits for RS256"

I do not want to change all RSA keys in every environment so I decided to use the flag allowInsecureKeySizes to bypass that new check.

My project is buillt with typescript and if I use that flag with in the options of jwt.sign() method I will see this error:

"TS2769: No overload matches this cal"

Reproduction

jwt.sign({}, privateKey, {
issuer: 'streetcrowd',
subject: provider,
algorithm: 'RS256',
allowInsecureKeySizes: true
});

This is the definition of SignOptions, as you can see, the required flag is missing:

export interface SignOptions {
algorithm?: Algorithm | undefined;
keyid?: string | undefined;
expiresIn?: string | number | undefined;
notBefore?: string | number | undefined;
audience?: string | string[] | undefined;
subject?: string | undefined;
issuer?: string | undefined;
jwtid?: string | undefined;
mutatePayload?: boolean | undefined;
noTimestamp?: boolean | undefined;
header?: JwtHeader | undefined;
encoding?: string | undefined;
}

image

Environment
  • jsonwebtoken 9.0.2
  • Node 18
Dominant language
JavaScript
Stars
18.2k
Forks
1.3k
PR merge metrics
No merged PRs in 30d

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from auth0/node-jsonwebtoken

All issues in auth0/node-jsonwebtoken

Similar issues

More JavaScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.