upvote
They did verify the signature, and it was correct according to the "none" algorithm.
reply
Argh, I missed that it actually uses the "none" algorithm. Yeah, the existence of that option is extremely dumb and it shouldn't be possible to use that. I misread the post and thought it was a regular JWT, but they simply didn't validate it.
reply
“Works as designed.”
reply
JWT is complicated.

Complexity is a spec failure in security issues.

It's that simple.

reply