Skip to content

Add insecure_decode_claims - #539

Merged
arckoor merged 1 commit into
Keats:masterfrom
arckoor:insecure-decode-claims
Sep 15, 2026
Merged

arckoor merged 1 commit into
Keats:masterfrom
arckoor:insecure-decode-claims

Conversation

@arckoor

@arckoor arckoor commented Sep 10, 2026

Copy link
Copy Markdown
Collaborator

Closes #538

@arckoor

arckoor commented Sep 13, 2026

Copy link
Copy Markdown
Collaborator Author

@douggynix just to confirm, this solves your problem?

@douggynix

Copy link
Copy Markdown

@douggynix just to confirm, this solves your problem?
@arckoor I add this line to my Cargo.toml

jsonwebtoken = { git = "https://github.com/arckoor/jsonwebtoken.git", branch = "insecure-decode-claims" , features = ["rust_crypto", "use_pem"] }

Thanks. it solves my issue. I tested it first wrongly before with insecure_decode. and I had to rerun it with
insecure_decode_claims.

I confirm this fixes my issue and I am able to decode unsecure tokens successfully.

Thanks a lot @arckoor for delivering the work and effort to put that into execution. you can merge and release that change.

@douggynix

douggynix commented Sep 14, 2026 •

Copy link
Copy Markdown

@arckoor : When this is going to be merged and released please?

@arckoor
arckoor merged commit 46690b5 into Keats:master Sep 15, 2026
10 checks passed
@arckoor
arckoor deleted the insecure-decode-claims branch September 15, 2026 21:23
@arckoor

arckoor commented Sep 15, 2026

Copy link
Copy Markdown
Collaborator Author

Whoops I forgot about this. @Keats can you do a release?

@douggynix

Copy link
Copy Markdown

thanks for the fix. Now, only the release remains :)

@douggynix

Copy link
Copy Markdown

@Keats : will this fix be part of the next release please?
as there is a PR from another open source project waiting for it:
avborup/fireplace#47

@Keats

Keats commented Sep 16, 2026

Copy link
Copy Markdown
Owner

Chill, it's already released

@douggynix

Copy link
Copy Markdown

Chill, it's already released

thanks. kindly

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

insecure_decode is failing decoding unsecure jwt that has alg value set with "none"

3 participants