[jboss-jira] [JBoss JIRA] (WFLY-13164) When "corrupted" public key is supplied to server, user is not informed

Darran Lofthouse (Jira) issues at jboss.org
Tue Mar 10 11:42:57 EDT 2020


     [ https://issues.redhat.com/browse/WFLY-13164?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Darran Lofthouse updated WFLY-13164:
------------------------------------
    Priority: Critical  (was: Blocker)


> When "corrupted" public key is supplied to server, user is not informed
> -----------------------------------------------------------------------
>
>                 Key: WFLY-13164
>                 URL: https://issues.redhat.com/browse/WFLY-13164
>             Project: WildFly
>          Issue Type: Bug
>          Components: MP JWT
>    Affects Versions: 19.0.0.Beta2, 20.0.0.Beta1
>            Reporter: Jan Kasik
>            Assignee: Darran Lofthouse
>            Priority: Critical
>         Attachments: CorruptedKeyTest.war
>
>
> When corrupted public key (a valid key cannot be extracted from the string value) is supplied to JWT verifier, user is not informed since there is no error message in log and clients receives 401 status code in response instead of an error code of 500.



--
This message was sent by Atlassian Jira
(v7.13.8#713008)


More information about the jboss-jira mailing list