From 05855ec9406455f3f619ca67a6f63a111e3d82ea Mon Sep 17 00:00:00 2001 From: Emmanuel Gautier Date: Sat, 5 Sep 2026 22:42:07 +0200 Subject: [PATCH] fix: generate token with alg not none when not vulnerable --- challenges/jwt-alg-none-bypass/main.go | 10 +++++++--- challenges/jwt-alg-none-bypass/serve/server.go | 5 ++++- 2 files changed, 11 insertions(+), 4 deletions(-) diff --git a/challenges/jwt-alg-none-bypass/main.go b/challenges/jwt-alg-none-bypass/main.go index 1b856c7..0e45579 100644 --- a/challenges/jwt-alg-none-bypass/main.go +++ b/challenges/jwt-alg-none-bypass/main.go @@ -9,13 +9,17 @@ import ( ) func generateToken(vulnerable bool) (string, error) { - token := jwt.NewWithClaims(jwt.SigningMethodNone, jwt.MapClaims{ + claims := jwt.MapClaims{ "sub": "2cb307ba-bb46-4194-854f-4774046d9c9b", "name": "John Doe", "iat": time.Now().Unix(), "exp": time.Now().Add(time.Hour).Unix(), - }) - return token.SignedString(jwt.UnsafeAllowNoneSignatureType) + } + if vulnerable { + token := jwt.NewWithClaims(jwt.SigningMethodNone, claims) + return token.SignedString(jwt.UnsafeAllowNoneSignatureType) + } + return jwt.NewWithClaims(jwt.SigningMethodHS256, claims).SignedString([]byte(serve.Secret)) } func main() { diff --git a/challenges/jwt-alg-none-bypass/serve/server.go b/challenges/jwt-alg-none-bypass/serve/server.go index 681382c..aebe89e 100644 --- a/challenges/jwt-alg-none-bypass/serve/server.go +++ b/challenges/jwt-alg-none-bypass/serve/server.go @@ -9,6 +9,9 @@ import ( "github.com/golang-jwt/jwt/v5" ) +// Secret is the HMAC secret used when the server runs in its fixed, non-vulnerable mode. +const Secret = "my_secret_key" + func RunServer(port string, vulnerable bool) { mux := http.NewServeMux() mux.HandleFunc("/", func(w http.ResponseWriter, r *http.Request) { @@ -28,7 +31,7 @@ func RunServer(port string, vulnerable bool) { return nil, fmt.Errorf("unexpected signing method: %v", token.Header["alg"]) } - return []byte("my_secret_key"), nil + return []byte(Secret), nil }) if token != nil && token.Valid {