Check for "none" alg in JWT signing
This commit is contained in:
parent
5b884806d2
commit
d625b8e3f3
|
@ -21,6 +21,11 @@ local function _verify_token(token, appId, appSecret, roomName, disableRoomNameC
|
||||||
return nil, err;
|
return nil, err;
|
||||||
end
|
end
|
||||||
|
|
||||||
|
local alg = claims["alg"];
|
||||||
|
if alg ~= nil and (alg == "none" or alg == "") then
|
||||||
|
return nil, "'alg' claim must not be empty";
|
||||||
|
end
|
||||||
|
|
||||||
local issClaim = claims["iss"];
|
local issClaim = claims["iss"];
|
||||||
if issClaim == nil then
|
if issClaim == nil then
|
||||||
return nil, "'iss' claim is missing";
|
return nil, "'iss' claim is missing";
|
||||||
|
|
Loading…
Reference in New Issue