Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: update token script (role_based_scopes_update_token) should reject tampered user-infor token #10536

Merged
merged 1 commit into from
Jan 2, 2025

Conversation

duttarnab
Copy link
Contributor

@duttarnab duttarnab commented Jan 1, 2025

Script Name: role_based_scopes_update_token
Script INUM: 2D3E.5A04

The script should throw bad request error when the verification of user-info JWT fails.
closes #10535

…ct the tampered user-info-jwt #10535

Signed-off-by: Arnab Dutta <[email protected]>
@duttarnab duttarnab requested a review from devrimyatar January 1, 2025 19:47
@mo-auto mo-auto added comp-docs Touching folder /docs kind-bug Issue or PR is a bug in existing functionality labels Jan 1, 2025
@duttarnab duttarnab requested review from yuriyz, yuriyzz and moabu January 2, 2025 07:36
@duttarnab duttarnab enabled auto-merge (squash) January 2, 2025 07:37
@duttarnab duttarnab changed the title fix: update token script (role_based_scopes_update_token) should reje… fix: update token script (role_based_scopes_update_token) should reject tampered user-infor token Jan 2, 2025
@duttarnab duttarnab merged commit 3cd5d88 into main Jan 2, 2025
2 checks passed
@duttarnab duttarnab deleted the jans-auth-server-issue-10535 branch January 2, 2025 13:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
comp-docs Touching folder /docs kind-bug Issue or PR is a bug in existing functionality
Projects
None yet
4 participants