logoalt Hacker News

meindnoch • today at 4:49 PM • 2 replies • view on HN

They did verify the signature, and it was correct according to the "none" algorithm.


Replies

fabian2k • today at 5:09 PM

Argh, I missed that it actually uses the "none" algorithm. Yeah, the existence of that option is extremely dumb and it shouldn't be possible to use that. I misread the post and thought it was a regular JWT, but they simply didn't validate it.

alex_suzuki • today at 4:55 PM

“Works as designed.”