Quantcast
Channel: JWT.io - Auth0 Community
Viewing all articles
Browse latest Browse all 152

JWT.io - HS256 validation false positivites AFTER initial verification?

$
0
0

After initial validation of JWT HS256, all subsequent input secrets (right or wrong) display Signature Verified.

I should be able to validate, remove a character then see Invalid Signature. Re-type that character and the signature is valid again.

Now luckily I used the JavaScript Web Crypto API to double check but JWT.io will just say yes to anything for HS256.

Why?

1 post - 1 participant

Read full topic


Viewing all articles
Browse latest Browse all 152

Trending Articles