Skip to content

Check a token issuer on validation #2

@stokito

Description

@stokito

Currently an attacker can send a token issued by Google while doing a FB auth.
So jwt-decode must also check that iss field is the same as for a provider.

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions