wow I am so surprised to hear once again how JWTs are terrible
Does this extend to OIDC? I’m not knowledgeable on the topic but it uses JWT right? Is it also prone to poor implementation? If you just error on alg=none does that solve it?
Idk if that's not too much of an oversimplification, maybe more like JWTs are an indicator/enabler of architecture level bugs?
Other commenters are suggesting you can’t blame the spec for end implementation mistakes, except that’s one of the many issues - JWT being so error-prone is a problem.
I use JWT just for handling of tokens, because it’s so well supported, but I won’t use it for anything more than token storage _because_ it is so vulnerable to mistakes.
The fact that mistakes are so easy to make is indicative of poor design in the spec itself.
Someone not verifying the signature at all is not a mistake where you can blame the JWT spec itself.