Problem
SessionConfig requires a 32-character secret_key, and jwt_algorithm accepts HS384 and HS512. RFC 7518 §3.2 requires a key at least as long as the hash output (48 / 64 bytes). PyJWT emits InsecureKeyLengthWarning on every encode and decode in that case, which with the middleware means every request.
Proposal
Check the key length once in JWTTokenSerializer.__init__ and emit one warning. Raising instead is breaking and tracked for 0.4.0.
Problem
SessionConfigrequires a 32-charactersecret_key, andjwt_algorithmaccepts HS384 and HS512. RFC 7518 §3.2 requires a key at least as long as the hash output (48 / 64 bytes). PyJWT emitsInsecureKeyLengthWarningon every encode and decode in that case, which with the middleware means every request.Proposal
Check the key length once in
JWTTokenSerializer.__init__and emit one warning. Raising instead is breaking and tracked for 0.4.0.