Jwt Security Review

securityskills/skills/web-appsec/auth/jwt-security-review

作者 securityskillsb2b6b5200ee91a249816df209a0b89ff01ae450a無授權條款收錄於 2026年10月9日更新於 2026年10月9日

Audit JSON Web Token implementations for algorithm confusion, weak secrets, missing validation, and token lifecycle flaws. Use when a codebase or API uses JWTs for auth.

僅含說明Security
AI 產生的概覽

稽核 JWT 驗證實作,檢查演算法混淆、弱密鑰、宣告驗證缺失與權杖生命週期缺陷。

功能
指導對 JSON Web Token 驗證進行端到端安全審查,涵蓋演算法處理、金鑰與密鑰強度、宣告驗證以及權杖生命週期。它列出具體攻擊檢查項,例如 alg:none 權杖、RS256 轉 HS256 混淆、jku/x5u 與 kid 注入,以及更新權杖重放。產出包含去識別化權杖樣本、受影響程式碼路徑與逐項修補建議的發現報告。
適用情境
適用於程式碼庫或 API 使用 JWT 進行驗證且需要安全稽核的情境。適合在發佈前或懷疑有缺陷時,審查權杖簽發、驗證以及更新或撤銷流程。
執行需求
僅為說明文件,不含指令碼或附帶資源。需要能存取待審查的 JWT 相關原始碼與設定。

JWT Security Review

Review JWT-based authentication end to end.

Review Areas

Algorithm Handling

  • Pin the expected algorithm server-side; reject alg: none outright
  • RS256→HS256 confusion: if the server verifies HMAC using the public key as the secret, an attacker can forge tokens. Confirm verification uses the correct key type per algorithm
  • Watch for jku/x5u header injection where the server fetches keys from an attacker-controllable URL
  • kid injection: path traversal or SQL/Command injection in key lookup

Key and Secret Strength

  • HS256 secrets: ≥32 bytes of entropy, not from wordlists (jwt-tools crack mode)
  • Keys rotated; old keys revoked rather than just unused

Claims Validation

  • exp and nbf enforced, clock skew bounded
  • iss and aud validated against expected values
  • Reject tokens with unexpected/extra privileged claims (e.g., admin: true) — parse then validate allowlist
  • Don't trust client-controlled role/uid claims if a server-side lookup exists

Token Lifecycle

  • Refresh tokens: rotation with reuse detection; stored hashed server-side
  • Revocation path exists for logout/password change/admin force-logout
  • Access tokens short-lived (≤15 min); no long-lived bearer tokens
  • Tokens not persisted in localStorage if XSS surface exists; prefer httpOnly cookies with CSRF protection
  • sub is stable and unambiguous (user ID, not email that can change)

Common Code Smells

jwt.decode(token)            // decode ≠ verify: signature never checkedjwt.verify(token, key)       // no algorithms option pinnedjwt.verify(token, key, { algorithms: ['*'] })

Test Cases

  1. Remove the signature; send alg: none token
  2. Flip alg to HS256 signed with the public key
  3. Expired/missing exp, wrong iss/aud
  4. Tampered claims with valid signature (e.g., escalate role)
  5. Replay a rotated refresh token — should invalidate the family

Output

Findings with token samples (redacted), affected code paths, and remediation per issue.

來源與署名

來源:securityskills/skills位於web-appsec/auth/jwt-security-review提交b2b6b52

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架