Skip to content

JWT验证存在伪造风险 #51

@NTLoner

Description

@NTLoner

在tools/jwt.go中明文显示了jwt的密钥 taoshihan,可利用其进行jwt伪造,伪造任意用户登录

f567390917243f5ddfdff41d5648e047

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions