Sitelet https://web.archive.org/web/20260530175448/https://github.com/github/codeql/pull/4638
Skip to content

JS: Add support for JWT libraries#4638

Merged
codeql-ci merged 10 commits into
github:mainfrom
erik-krogh:jwt
Nov 16, 2020
Merged

JS: Add support for JWT libraries#4638
codeql-ci merged 10 commits into
github:mainfrom
erik-krogh:jwt

Conversation

@erik-krogh
Copy link
Copy Markdown
Contributor

No description provided.

Comment thread javascript/2020-11-09-jwt.md Outdated
Comment thread javascript/ql/src/semmle/javascript/frameworks/JWT.qll Outdated
Comment thread javascript/ql/src/semmle/javascript/frameworks/JWT.qll Outdated
@erik-krogh erik-krogh marked this pull request as ready for review November 10, 2020 10:44
@erik-krogh erik-krogh requested a review from a team as a code owner November 10, 2020 10:44
}

/**
* The public/private key for a JWT as a `CredentialsExpr`.
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should we really treat the public key as a credential? Doesn't seem like a security issue to hard-code that.

Copy link
Copy Markdown
Contributor Author

@erik-krogh erik-krogh Nov 11, 2020 •

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It can also use symmetric encryption.
That is actually the default.

Copy link
Copy Markdown
Contributor

@asgerf asgerf Nov 12, 2020 •

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I still think we should remove it from verify. If symmetric encryption is used we should still be able to pick up the same key via the sign call.

Comment thread javascript/2020-11-09-jwt.md Outdated
@codeql-ci codeql-ci merged commit 13edc37 into github:main Nov 16, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants