Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

`isExpired` doesn't correctly validate `iat`

Aperta
#100 9 commenti 1 reazione 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
3/5
Tempo stimato
1-2 giorni
Idoneità per principianti
35/100
Tipo di issue
Bug
Chiarezza
Abbastanza chiara
Stato di attività
Ferma
Stack tecnologico
android, java

Direzione di ricerca

Inizia in lib/src/main/java/com/auth0/android/jwt/JWT.java, intorno alle righe 161-171, dove isExpired calcola i limiti temporali e convalida iat. Riproduci il caso segnalato con un JWT utilizzato immediatamente dopo la creazione, quindi verifica che un iat valido venga accettato senza indebolire la leeway o i controlli di scadenza esistenti.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

bug
Checklist
  • I have looked into the Readme and Examples, and have not found a suitable solution or answer.
  • I have looked into the API documentation and have not found a suitable solution or answer.
  • I have searched the issues and have not found a suitable solution or answer.
  • I have searched the Auth0 Community forums and have not found a suitable solution or answer.
  • I agree to the terms within the Auth0 Code of Conduct.
Description

Due to the way the isExpired was implemented, the iat is invalid for the first 0.5 seconds of JWT existence, given this code here:

https://github.com/auth0/JWTDecode.Android/blob/df3eb302a2164abaef36a33fded58f99f516c731/lib/src/main/java/com/auth0/android/jwt/JWT.java#L161-L171

The line 165 is rounding the current time. If your server is very fast and generate, transmit and reaches your application in less than 0.5s, the futureToday.before(payload.iat) on the line 169 returns false. But the JWT is totally valid.

Solutions:

  • Also compare futureToday == payload.iat.
  • Stop truncating the todayTime.

I reimplemented the validation in Kotlin and added some logs:

fun isExpired(jwt: JWT, leeway: Int): Boolean {
  val todayTime = (floor((Date().time / 1000).toDouble()) * 1000).toLong() //truncate millis
  val futureToday = Date(todayTime + leeway * 1000)
  val pastToday = Date(todayTime - leeway * 1000)
  val expValid = jwt.expiresAt == null || !pastToday.after(jwt.expiresAt)
  val iatValid = jwt.issuedAt == null || !futureToday.before(jwt.issuedAt)
  return !expValid || !iatValid
}

This prints:

todayTime 1740576730000
futureToday 1740576730000
pastToday 1740576730000
expValid true
iatValid false
Reproduction

Probably create the JWT and use it straightway, it will fail on the iat.

Additional context

No response

JWTDecode.Android version

2.0.2

Android version(s)

API 32

Lingua principale
Java
Stelle
457
Fork
81
Merge medio
6h 18m
PR unite (30g)
4

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di auth0/JWTDecode.Android

Tutte le issue di auth0/JWTDecode.Android

Issue simili

Altre issue su Java

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.