Skip to content

Warn when the JWT HMAC secret is shorter than the hash output #116

Description

@allen0099

Problem

SessionConfig requires a 32-character secret_key, and jwt_algorithm accepts HS384 and HS512. RFC 7518 §3.2 requires a key at least as long as the hash output (48 / 64 bytes). PyJWT emits InsecureKeyLengthWarning on every encode and decode in that case, which with the middleware means every request.

Proposal

Check the key length once in JWTTokenSerializer.__init__ and emit one warning. Raising instead is breaking and tracked for 0.4.0.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestsessionSession management subsystem

    Projects

    No projects

      Milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions