Skip to content

0.4.0: reject JWT HMAC secrets shorter than the hash output #129

Description

@allen0099

Follow-up to #116.

Follow-up to the 0.3.8 warning: raise at startup when jwt_algorithm is HS384 / HS512 and the secret is shorter than 48 / 64 bytes (RFC 7518 §3.2).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    breaking-changeChanges public behaviour or API; needs a minor/major releasesessionSession management subsystem

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions