Code RoomJWT kid header injection
HardPrep Room Coding #2058

JWT kid header injection

Code reviewSecuritySenior–Staff~24 min

Review this Node JWT verifier that resolves the signing key from the token header.

What a strong answer looks like

Separate real bugs from style. Rank issues by severity, point at the root cause rather than the symptom, and suggest a concrete fix, specific and kind.

0:00 of about 24 min
Mark a line and say what kind of problem it is.0 findings
1const jwt = require('jsonwebtoken');
2const fs = require('fs');
3 
4function verify(token) {
5 const { header } = jwt.decode(token, { complete: true });
6 const keyPath = `/etc/keys/${header.kid}.pem`;
7 const key = fs.readFileSync(keyPath, 'utf8');
8 return jwt.verify(token, key, { algorithms: ['RS256'] });
9}
Which questions mattered is sealed until you submit. Telling you now would just be handing over the edge cases.