Skip to content

Commit 91d8ac5

Browse files
Fix logic that exposes algorithm confusion vulnerability (#329)
* Fix logic that exposes algorithm confusion vulnerability --------- Co-authored-by: Roshan Piyush <[email protected]>
1 parent 116bb9a commit 91d8ac5

File tree

1 file changed

+3
-3
lines changed

1 file changed

+3
-3
lines changed

services/identity/src/main/java/com/crapi/config/JwtProvider.java

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -189,10 +189,10 @@ public boolean validateJwtToken(String authToken) {
189189
log.debug("Key from JKU: " + verificationKey.toJSONString());
190190
verifier = new RSASSAVerifier(verificationKey);
191191
}
192-
valid = signedJWT.verify(verifier);
193-
log.debug("JWT valid?: " + valid);
194-
return valid;
195192
}
193+
valid = signedJWT.verify(verifier);
194+
log.debug("JWT valid?: " + valid);
195+
return valid;
196196

197197
} catch (ParseException e) {
198198
try {

0 commit comments

Comments
 (0)