Security
The JWT Library That Accepted alg none for Four Months
A penetration test report landed with a finding rated critical. The tester had taken a valid token from their own low privilege account, changed the payload, set the header algorithm to none, stripped the signature, and been granted access to another tenant's data. We had read the advisories.