Skip to content

Update docs to include instructions for the algorithm parameter.#108

Merged
excpt merged 1 commit intojwt:masterfrom
aarongray:master
Oct 7, 2015
Merged

Update docs to include instructions for the algorithm parameter.#108
excpt merged 1 commit intojwt:masterfrom
aarongray:master

Conversation

@aarongray
Copy link
Copy Markdown
Contributor

This parameter is necessary to prevent attackers from bypassing the
algorithm verification step.

See:
https://auth0.com/blog/2015/03/31/critical-vulnerabilities-in-json-web-token-libraries/
#76
#71
#107

@review-ninja
Copy link
Copy Markdown

ReviewNinja

excpt added a commit that referenced this pull request Oct 7, 2015
Update docs to include instructions for the algorithm parameter.
@excpt excpt merged commit 4630752 into jwt:master Oct 7, 2015
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants