`isExpired` doesn't correctly validate `iat`
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 3/5
- Tempo stimato
- 1-2 giorni
- Idoneità per principianti
- 35/100
- Tipo di issue
- Bug
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Ferma
- Ambito
- authentication, security
Direzione di ricerca
Inizia in lib/src/main/java/com/auth0/android/jwt/JWT.java, intorno alle righe 161-171, dove isExpired calcola i limiti temporali e convalida iat. Riproduci il caso segnalato con un JWT utilizzato immediatamente dopo la creazione, quindi verifica che un iat valido venga accettato senza indebolire la leeway o i controlli di scadenza esistenti.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Checklist
- I have looked into the Readme and Examples, and have not found a suitable solution or answer.
- I have looked into the API documentation and have not found a suitable solution or answer.
- I have searched the issues and have not found a suitable solution or answer.
- I have searched the Auth0 Community forums and have not found a suitable solution or answer.
- I agree to the terms within the Auth0 Code of Conduct.
Description
Due to the way the isExpired was implemented, the iat is invalid for the first 0.5 seconds of JWT existence, given this code here:
The line 165 is rounding the current time. If your server is very fast and generate, transmit and reaches your application in less than 0.5s, the futureToday.before(payload.iat) on the line 169 returns false. But the JWT is totally valid.
Solutions:
- Also compare
futureToday == payload.iat. - Stop truncating the
todayTime.
I reimplemented the validation in Kotlin and added some logs:
fun isExpired(jwt: JWT, leeway: Int): Boolean {
val todayTime = (floor((Date().time / 1000).toDouble()) * 1000).toLong() //truncate millis
val futureToday = Date(todayTime + leeway * 1000)
val pastToday = Date(todayTime - leeway * 1000)
val expValid = jwt.expiresAt == null || !pastToday.after(jwt.expiresAt)
val iatValid = jwt.issuedAt == null || !futureToday.before(jwt.issuedAt)
return !expValid || !iatValid
}
This prints:
todayTime 1740576730000
futureToday 1740576730000
pastToday 1740576730000
expValid true
iatValid false
Reproduction
Probably create the JWT and use it straightway, it will fail on the iat.
Additional context
No response
JWTDecode.Android version
2.0.2
Android version(s)
API 32
- Lingua principale
- Java
- Stelle
- 457
- Fork
- 81
- Merge medio
- 6h 18m
- PR unite (30g)
- 4
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di auth0/JWTDecode.Android
-
feature request
Difficoltà 4/5 3-5 giorni Idoneità per principianti 35/100
auth0/JWTDecode.Android#82 · 10 reazioni ·
-
Include proguard consumer directives for R8 compatibilityForse di nuovo libera Una pull request per questa issue è stata chiusa senza essere unita. Apertafeature request
Difficoltà 2/5 1-3 ore Idoneità per principianti 52/100
auth0/JWTDecode.Android#72 · 7 commenti · 3 reazioni ·
Tutte le issue di auth0/JWTDecode.Android
Issue simili
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 82/100
mit-cml/appinventor-sources#4155 ·
I maintainer di solito rispondono entro 1 giorno
-
[Doc] - Creation du READMEAperta
Difficoltà 1/5 1-3 ore Idoneità per principianti 62/100
Hira-shi/PW1-DAI-Carrel-Egal-Eyer#28 ·
I maintainer di solito rispondono entro 1 giorno
-
`GET /v1/event/token/{uuid}` can report a BOM upload as done before policy evaluation and metrics have finishedForse già presa @Zargath l’ha presa oggi. Apertadefect in triage
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
DependencyTrack/dependency-track#7646 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
floci-io/floci#5425 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
objectionary/eo-graphs#80 ·