Repository navigation
Expand file tree
/
Copy pathnone.go
More file actions
39 lines (33 loc) · 1.45 KB
/
Copy pathnone.go
File metadata and controls
39 lines (33 loc) · 1.45 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
package jwt
import "bytes"
// algNONE implements the Alg interface for unsecured JWTs.
// This algorithm provides no cryptographic security and should only be used
// when security is not a concern, such as for debugging or client-side data.
//
// WARNING: Tokens signed with "none" algorithm can be forged by anyone.
// Never use this algorithm for security-sensitive applications.
type algNONE struct{}
// Name returns "none", the identifier RFC 7518 section 3.6 gives the unsecured
// algorithm.
//
// It returned "NONE" before, in capitals, which no other implementation recognises. A
// token this package produced under that name was not a valid unsecured JWT and could not
// be read anywhere else, and a conforming token naming "none" was never accepted here.
func (a *algNONE) Name() string {
return "none"
}
// Sign implements the Alg interface for the "none" algorithm.
// It returns an empty signature since no cryptographic signing is performed.
// The key parameter is ignored and can be nil.
func (a *algNONE) Sign(key PrivateKey, headerAndPayload []byte) ([]byte, error) {
return nil, nil
}
// Verify implements the Alg interface for the "none" algorithm.
// It verifies that the signature is empty, as required by RFC 7515.
// Returns ErrTokenSignature if the signature is not empty.
func (a *algNONE) Verify(key PublicKey, headerAndPayload []byte, signature []byte) error {
if !bytes.Equal(signature, []byte{}) {
return ErrTokenSignature
}
return nil
}