Skip to content

don't croak on an unknown zip method while unzipping the payload#39

Open
MichaelDaum wants to merge 2 commits intoDCIT:masterfrom
MichaelDaum:master
Open

don't croak on an unknown zip method while unzipping the payload#39
MichaelDaum wants to merge 2 commits intoDCIT:masterfrom
MichaelDaum:master

Conversation

@MichaelDaum
Copy link

LinkedIn's OpenID puts an "RS256" into the "zip" property of the JWT header. Which might be wrong obviously as the rest of the payload is uncompressed. So better ignore this and return the payload as is.

LinkedIn's OpenID puts an "RS256" into the "zip" property of the JWT
header. Which might be wrong obviously as the rest of the payload is
uncompressed. So better ignore this and return the payload as is.
@karel-m
Copy link
Contributor

karel-m commented Aug 17, 2024

The standard https://datatracker.ietf.org/doc/html/rfc7516#section-4.1.3 says:

Use of this Header Parameter is OPTIONAL.
This Header Parameter MUST be understood
and processed by implementations.

To me it sounds like when the "zip" properties is present but we do not understand its content we should stop/fail/croak.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants