Skip to content
Better HN
Top
New
Best
Ask
Show
Jobs
Search
⌘K
0 points
abritinthebay
8y ago
0 comments
Share
That’s only true of JWT if you allow your server to
accept
all algorithms.
You don’t actually have to.
undefined | Better HN
0 comments
default
newest
oldest
rblatz
8y ago
Correct, your token authority should specify which algorithms are valid, and your clients should self configure via a secure back channel to only accept the algorithms your token authority issues.
abritinthebay
OP
8y ago
Exactly! JWT is a much misunderstood system it seems. Though it doesn’t exactly help itself by being quite complex
j
/
k
navigate · click thread line to collapse