fix(sdk): verify JWT claims before returning them - #121
Conversation
|
🐕 Review complete — View session on Shuni Portal 🐾 |
🐕 Suggested ReviewersThe review assignment prioritizes recent contributors who have worked on the affected files, with a focus on those demonstrating breadth across the changed areas. Since only one contributor has recent activity on all relevant files, they are recommended for thorough review.
Suggested by Shuni based on git history and PR context. Names are not @-mentioned to avoid notifying anyone — request a review from whoever fits best. |
There was a problem hiding this comment.
🐕 Shuni's Review
Makes getClaims run full JWKS signature verification (via validateJWT) instead of returning the unverified payload, and locks down the raw parser. Solid security fix — good bones!
Sniffed out 1 issue:
- 1 🟢 LOW:
getClaimsverifies signature/issuer but not expiration
Retry logic, privatizing parseToken (no external callers), and the forged-token regression test all check out. Woof!
2d2cc6e to
d75f37e
Compare
Summary
Verification