Skip to content

auth: Bearer JWT is not interoperable with standard HS256 / external IdP tokens #301

Description

@Sorcecoder

Surfaced building a jerrycan app for a performance study against a standard HS256 token.

Two independent breaks from standard JWT:

  1. Key derivation. Bearer<SessionUser> verifies with derive_key(JERRYCAN_SECRET, "jwt") = SHA256(secret ++ "jwt") (jerrycan-auth/src/jwt.rs, guard.rs, lib.rs derive_key), not the raw JERRYCAN_SECRET. No secret value makes it accept a token signed with the raw secret.
  2. Claims. Bearer<SessionUser> deserializes the whole payload into SessionUser { id, role } — it requires id and role and ignores the standard sub claim.

Impact: a jerrycan app cannot accept a JWT minted by any standard library / external IdP (Auth0, Cognito, Supabase, a plain jwt.encode) — the token must be HS256 over SHA256(secret+"jwt") with {id, role}. Interop with external auth is a common need.

Suggested: document this loudly, and/or offer a standard-interop mode (verify against the raw secret, accept sub as the id). Found via the perf/migration eval.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions