Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Clearly trying to be too general. I wrote a tiny JWT validator before that only allows a very small subset of algorithms because I wasn't expecting the JWTs it would handle to have anything else, and obviously not "none".
 help



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: