Skip to content

fix(session): reject asymmetric JWT algorithms the built-in serializer cannot sign - #92

Merged
allen0099 merged 1 commit into
masterfrom
fix/jwt-asymmetric-algorithms
Sep 25, 2026
Merged

allen0099 merged 1 commit into
masterfrom
fix/jwt-asymmetric-algorithms

Conversation

@allen0099

@allen0099 allen0099 commented Sep 25, 2026 •

Copy link
Copy Markdown
Owner

Closes #86. This is option 1 from the issue: validate early.

Problem

SessionConfig.jwt_algorithm accepts RS*, ES*, PS* and EdDSA, but JWTTokenSerializer signs and verifies with the single secret_key string. Such a configuration started up fine, then the first create_session() failed inside PyJWT (InvalidKeyError).

Change

  • JWT_HMAC_ALGORITHMS (HS256/HS384/HS512) in session/config.py lists what the built-in serializer can use.
  • JWTTokenSerializer.__init__ raises ValueError for any other algorithm. Because SessionManager builds the serializer in its constructor, the error now appears at startup. The message names both fixes: use an HS algorithm, or pass a custom token_serializer.
  • SessionConfig still accepts every algorithm it accepted before. A SessionManager that gets its own token_serializer never builds the built-in serializer, so it is unaffected.
  • The only configurations that now fail are ones that could never create a session. That is why this is a fix rather than a breaking change.
  • docs/JWT_CLAIMS.md and docs/SESSION.md describe the new behavior. CHANGELOG.md gains a Fixed entry.

Real key-pair support (option 2, jwt_private_key/jwt_public_key) is left for a later feature.

Tests

  • Asymmetric algorithms are rejected by the serializer (6 cases).
  • SessionManager fails at construction for RS256.
  • A custom serializer with RS256 is still accepted.
  • HS256/384/512 round-trip through real PyJWT.
  • On the old code, 7 of these 11 fail (the rejection and startup cases); the other 4 describe behavior that already worked.
  • Full suite: 531 passed and 146 skipped. The skips are the Redis/Memcached live suites; no test servers were running. Coverage is 92%.

Note

Rebased onto master after #91 merged: the ### Fixed section under [Unreleased] now holds both entries.

…r cannot sign

JWTTokenSerializer signs and verifies with the secret_key string, so RS*,
ES*, PS* and EdDSA were accepted by SessionConfig and then failed inside
PyJWT on the first create_session(). The serializer now raises ValueError
when it is built with one of them, so the SessionManager fails at startup
with a message that points to the HMAC algorithms or a custom
token_serializer. Configurations that pass their own serializer are
unaffected.

Closes #86
@allen0099
allen0099 force-pushed the fix/jwt-asymmetric-algorithms branch from c604406 to 34b03dd Compare September 25, 2026 08:31
@allen0099
allen0099 merged commit 41f331b into master Sep 25, 2026
9 of 10 checks passed
@allen0099
allen0099 deleted the fix/jwt-asymmetric-algorithms branch September 25, 2026 08:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

JWT sessions accept asymmetric algorithms that the built-in serializer cannot use

1 participant