Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(jans-auth-server): update token script (role_based_scopes_update_token) should reject the tampered user-info-jwt #10535

Closed
1 task done
duttarnab opened this issue Jan 1, 2025 · 0 comments · Fixed by #10536
Assignees
Labels
comp-jans-auth-server Component affected by issue or PR kind-bug Issue or PR is a bug in existing functionality

Comments

@duttarnab
Copy link
Contributor

duttarnab commented Jan 1, 2025

parent issue #GluuFederation/flex#1952

Script Name: role_based_scopes_update_token
Script INUM: 2D3E.5A04

  • The script should throw bad request error when the verification of user-info JWT fails.
@duttarnab duttarnab added comp-jans-auth-server Component affected by issue or PR kind-bug Issue or PR is a bug in existing functionality labels Jan 1, 2025
duttarnab added a commit that referenced this issue Jan 1, 2025
…ct the tampered user-info-jwt #10535

Signed-off-by: Arnab Dutta <[email protected]>
duttarnab added a commit that referenced this issue Jan 2, 2025
#10536)

fix: update token script (role_based_scopes_update_token) should reject the tampered user-info-jwt #10535

Signed-off-by: Arnab Dutta <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
comp-jans-auth-server Component affected by issue or PR kind-bug Issue or PR is a bug in existing functionality
Projects
None yet
2 participants