[management, proxy] Enforce strict base64url decoding for JWT validation (#7554)

This commit is contained in:
Bethuel Mmbaga
2026-09-29 11:46:25 +03:00
committed by GitHub
parent e830903a94
commit a2919e26dd
4 changed files with 72 additions and 4 deletions
+1 -2
View File
@@ -18,7 +18,6 @@ import (
"time"
"github.com/golang-jwt/jwt/v5"
log "github.com/sirupsen/logrus"
)
@@ -217,8 +216,8 @@ func (v *Validator) ValidateAndParse(ctx context.Context, token string) (*jwt.To
jwt.WithAudience(v.audienceList...),
jwt.WithIssuer(v.issuer),
jwt.WithIssuedAt(),
jwt.WithStrictDecoding(),
)
// Check if there was an error in parsing...
if err != nil {
err = fmt.Errorf("%w: %s", errTokenParsing, err)