Surfaced building a jerrycan app for a performance study against a standard HS256 token.
Two independent breaks from standard JWT:
- Key derivation.
Bearer<SessionUser> verifies with derive_key(JERRYCAN_SECRET, "jwt") = SHA256(secret ++ "jwt") (jerrycan-auth/src/jwt.rs, guard.rs, lib.rs derive_key), not the raw JERRYCAN_SECRET. No secret value makes it accept a token signed with the raw secret.
- Claims.
Bearer<SessionUser> deserializes the whole payload into SessionUser { id, role } — it requires id and role and ignores the standard sub claim.
Impact: a jerrycan app cannot accept a JWT minted by any standard library / external IdP (Auth0, Cognito, Supabase, a plain jwt.encode) — the token must be HS256 over SHA256(secret+"jwt") with {id, role}. Interop with external auth is a common need.
Suggested: document this loudly, and/or offer a standard-interop mode (verify against the raw secret, accept sub as the id). Found via the perf/migration eval.
Surfaced building a jerrycan app for a performance study against a standard HS256 token.
Two independent breaks from standard JWT:
Bearer<SessionUser>verifies withderive_key(JERRYCAN_SECRET, "jwt")=SHA256(secret ++ "jwt")(jerrycan-auth/src/jwt.rs,guard.rs,lib.rs derive_key), not the rawJERRYCAN_SECRET. No secret value makes it accept a token signed with the raw secret.Bearer<SessionUser>deserializes the whole payload intoSessionUser { id, role }— it requiresidandroleand ignores the standardsubclaim.Impact: a jerrycan app cannot accept a JWT minted by any standard library / external IdP (Auth0, Cognito, Supabase, a plain
jwt.encode) — the token must be HS256 overSHA256(secret+"jwt")with{id, role}. Interop with external auth is a common need.Suggested: document this loudly, and/or offer a standard-interop mode (verify against the raw secret, accept
subas the id). Found via the perf/migration eval.