Skip to content

feat(session)!: reject JWT HMAC secrets shorter than the hash output - #418

Open
allen0099 wants to merge 1 commit into
masterfrom
feat/129-reject-short-jwt-secrets
Open

allen0099 wants to merge 1 commit into
masterfrom
feat/129-reject-short-jwt-secrets

Conversation

@allen0099

Copy link
Copy Markdown
Owner

Closes #129

Summary

  • JWTTokenSerializer (and so SessionManager with token_format="jwt") raises ValueError when jwt_algorithm is HS384 or HS512 and secret_key is shorter than 48 or 64 bytes in UTF-8 (RFC 7518 §3.2). This replaces the 0.3.x UserWarning.
  • The check runs right after the asymmetric-algorithm check and before PyJWT is imported, so a misconfiguration is reported even without the jwt extra.
  • A custom token_serializer holds its own key and is not checked. HS256 is unaffected (SessionConfig already requires 32 characters).
  • Docs: SESSION.md and MIGRATING_0_4.md#jwt-secret (en/zh-TW); changelog fragment 129.changed.md.

Tests

  • Rejection and acceptance at each boundary for HS256/HS384/HS512, counted in UTF-8 bytes (multibyte keys on both sides of the limit).
  • Rejection when SessionManager is built, before PyJWT is needed, and a custom serializer bypassing the check.
  • Mutation-checked: <= instead of <, counting characters instead of bytes, dropping the raise, and moving the check after the PyJWT import each fail a test.

JWTTokenSerializer raises ValueError when jwt_algorithm is HS384 or
HS512 and secret_key is shorter than 48 or 64 UTF-8 bytes (RFC 7518
section 3.2). The check runs before PyJWT is imported, so the
configuration error comes first. A custom token_serializer holds its own
key and is not checked.

BREAKING CHANGE: a SessionManager with token_format="jwt", HS384/HS512
and a short secret_key no longer starts. 0.3.x warned with a
UserWarning; use a longer key or HS256.

Closes #129
@allen0099 allen0099 added this to the 0.4.0 milestone Sep 30, 2026
@allen0099 allen0099 added session Session management subsystem breaking-change Changes public behaviour or API; needs a minor/major release labels Sep 30, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

breaking-change Changes public behaviour or API; needs a minor/major release session Session management subsystem

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0.4.0: reject JWT HMAC secrets shorter than the hash output

1 participant