Enable header.typ assertion
评估
- 难度
- 3/5
- 预计耗时
- 1-2 天
- 新手友好度
- 45/100
- Issue 类型
- 功能
- 描述清晰度
- 基本清楚
- 活跃度
- 停滞
- 技术栈
- javascript
调研方向
首先跟踪 JWT 验证入口点以及验证选项的解析方式,然后检查令牌标头的验证位置。使用 RFC 9068 确认预期的 typ 值,并将完成标准定义为:在配置的类型缺失或不同时验证失败;未配置类型时,现有行为保持不变。
由索引模型根据 Issue 内容生成。
描述
Describe the problem you'd like to have solved
I would like to be able to differentiate between access tokens and identity tokens, and specifically to fail JWT validation if the token is not an access token.
Describe the ideal solution
We can assert that a token is an access token but checking the typ header for the value at+jwt. See https://datatracker.ietf.org/doc/rfc9068/
I would like to have a typ option which I could set to the required value, with JWT verification failing if the expected type is not found in the header.
Alternatives and current work-arounds
Do not share identity token to clients, so they cannot present id_token for authentication.
Additional context
n/a
- 主要语言
- JavaScript
- 星标
- 18.2k
- 派生
- 1.3k
- PR 合并指标
- 30 天内没有已合并 PR
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 没有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
auth0/node-jsonwebtoken 的其他 Issue
-
难度 2/5 1-3 小时 新手友好度 72/100
auth0/node-jsonwebtoken#1042 · 1 条评论 ·
-
`jwt.sign()` callback is executed twice for "The payload already has an "..." property" errors可能已有人在做 @cobyfrombrooklyn-bot 于 228 天前认领。 未关闭
难度 2/5 1-3 小时 新手友好度 84/100
auth0/node-jsonwebtoken#1000 · 2 条评论 · 1 个 reaction ·
-
难度 4/5 3-5 天 新手友好度 45/100
auth0/node-jsonwebtoken#1048 ·
-
verify() resolves a string secret by attempting createPublicKey() first, costing 4x-52x on the HS* path可能已有人在做 @Hashim1999164 于 22 天前认领。 未关闭
难度 4/5 3-5 天 新手友好度 65/100
auth0/node-jsonwebtoken#1046 ·
-
难度 5/5 一周以上 新手友好度 10/100
auth0/node-jsonwebtoken#1034 ·
查看 auth0/node-jsonwebtoken 的全部 Issue
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 66/100
druxt/umami.demo.druxtjs.org#527 ·
维护者通常 9 天内回复
-
难度 2/5 1-3 小时 新手友好度 62/100
NuSkooler/enigma-bbs#907 ·
维护者通常 1 天内回复
-
documentation good first issue
难度 2/5 1-3 小时 新手友好度 72/100
-
good first issue
难度 2/5 1-3 小时 新手友好度 70/100
-
documentation good first issue help wanted
难度 2/5 1-3 小时 新手友好度 75/100
维护者通常 1 天内回复