Jwt-auth: Possible security bug

Created on 22 Apr 2017  路  2Comments  路  Source: tymondesigns/jwt-auth

I'm using jwt-auth in two separate applications with Laravel 5.3. And I have verified that I can authenticate in one of the applications with a token generated by the other application, in that case the application authenticates me as long as I have a user with the same id.

I have reviewed the jwt-auth code and found that to authenticate it only verifies that the token can be decoded, and in that case logs the user through the id.

I recommend that the encoding be done in combination with the key of the application generated by key: generate.

Please correct me if I am wrong.

Most helpful comment

In your .env file, do you have a two different JWT_SECRET?

All 2 comments

In your .env file, do you have a two different JWT_SECRET?

Sorry is an copy/paste issue. I just regenerate the JWT_SECRET and is working properly now.

Thanks !

Was this page helpful?
0 / 5 - 0 ratings

Related issues

mihailo-misic picture mihailo-misic  路  3Comments

phamduong picture phamduong  路  3Comments

heroghost picture heroghost  路  3Comments

CBR09 picture CBR09  路  3Comments

johncloud200 picture johncloud200  路  3Comments