Skip to content

Conversation

@kernelshard
Copy link
Owner

No description provided.

kernelshard and others added 12 commits August 9, 2025 19:29
- Add JWT algorithm validation to prevent algorithm confusion attacks
- Fix email claim validation in token validation
- Remove debug fmt.Println() from user storage
- Improve security error logging

Fixes critical JWT security vulnerabilities in auth service
use dependency injected value and methods, rather than directly from library
@kernelshard kernelshard merged commit 13b8136 into main Aug 17, 2025
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants