Regex audience matching without anchors is a security footgun
Evaluación
- Dificultad
- 2/5
- Tiempo estimado
- 1-3 horas
- Aptitud para principiantes
- 52/100
- Tipo de issue
- Documentación
- Claridad
- Bastante claro
- Estado de actividad
- Tranquilo
- Stack tecnológico
- javascript, node.js
- Área
- authentication, security
Línea de trabajo
Comienza con la comprobación de audience en verify.js y la sección de audience del README. Revisa cómo se describen actualmente las audiences de tipo string y RegExp, y confirma después qué comportamiento propuesto quieren los maintainers. La implementación debería hacer explícitas las implicaciones de seguridad de las audiences regex no ancladas, actualizando también la cobertura de verificación relacionada si fuera necesario.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Summary
When options.audience contains a RegExp, verify() calls audience.test(targetAudience) without enforcing that the regex is anchored. This means a developer who writes:
jwt.verify(token, secret, { audience: /api\.myapp\.com/ });
will inadvertently accept tokens with audiences like evil-api.myapp.com.attacker.com — the . matches any character and there are no ^/$ anchors.
The string comparison path (audience === targetAudience) is strict. The regex path silently shifts the security burden to the caller.
Reproduction
const jwt = require('jsonwebtoken');
const secret = 'test-secret';
const token = jwt.sign({ aud: 'evil-api.myapp.com.attacker.com' }, secret);
// Developer intends to only accept "api.myapp.com"
jwt.verify(token, secret, { audience: /api\.myapp\.com/ }, (err, decoded) => {
console.log(err); // null — no error!
console.log(decoded); // token accepted despite malicious audience
});
Impact
This is not a vulnerability in the library itself — the regex works as designed. But it's a footgun: developers who mix string and regex audience checks may not realize the security model differs between the two paths. The string path is exact-match. The regex path accepts partial matches unless the developer manually adds ^ and $.
Given that audience validation is a security-critical check, the gap between "looks like it works" and "actually secure" is a concern.
Suggestions (pick any)
- Document it prominently — Add a note to the README's audience section warning that regex audiences must be anchored to avoid partial matches.
- Warn on unanchored regexes — If the regex source doesn't start with
^or end with$, emit a console warning or throw. - Auto-anchor — Wrap unanchored regexes in
^(?:...)$before testing. This would be a breaking change for anyone relying on partial matches intentionally.
Option 1 is the lowest-friction fix. Option 2 provides defense-in-depth without breaking existing behavior.
Relevant code
return audiences.some(function (audience) {
return audience instanceof RegExp ? audience.test(targetAudience) : audience === targetAudience;
});
- Lenguaje dominante
- JavaScript
- Estrellas
- 18.2k
- Forks
- 1.3k
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Sin plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de auth0/node-jsonwebtoken
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
auth0/node-jsonwebtoken#1042 · 1 comentario ·
-
`jwt.sign()` callback is executed twice for "The payload already has an "..." property" errorsPosiblemente ocupada @cobyfrombrooklyn-bot la tomó hace 228 días. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
auth0/node-jsonwebtoken#1000 · 2 comentarios · 1 reacción ·
-
Dificultad 4/5 3-5 días Aptitud para principiantes 45/100
auth0/node-jsonwebtoken#1048 ·
-
verify() resolves a string secret by attempting createPublicKey() first, costing 4x-52x on the HS* pathPosiblemente ocupada @Hashim1999164 la tomó hace 22 días. Abierto
Dificultad 4/5 3-5 días Aptitud para principiantes 65/100
auth0/node-jsonwebtoken#1046 ·
-
Dificultad 5/5 Más de una semana Aptitud para principiantes 10/100
auth0/node-jsonwebtoken#1034 ·
Todos los issues de auth0/node-jsonwebtoken
Issues similares
-
documentation good first issue help wanted
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
Los mantenedores suelen responder en 1 día
-
bug release:v5.56
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
Jason-Vaughan/TangleClaw#2270 ·
Los mantenedores suelen responder en 1 día
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 66/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
style-dictionary/style-dictionary#1773 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
SignalK/signalk-server#3143 ·
Los mantenedores suelen responder en 1 día