Fixed
Details
Assignee
Henri MikkonenHenri MikkonenReporter
Henri MikkonenHenri MikkonenComponents
Fix versions
Affects versions
Details
Details
Assignee
Henri Mikkonen
Henri MikkonenReporter
Henri Mikkonen
Henri MikkonenComponents
Fix versions
Affects versions
Created April 3, 2024 at 3:24 PM
Updated April 11, 2024 at 9:36 AM
Resolved April 3, 2024 at 4:16 PM
When implicit authorization flow involves ID token and JWT access token issuance, the JWT access token is not signed. It makes the access token useless, as OP’s own user info endpoint (the access token’s sole audience) won’t accept unsigned JWT access tokens.
This case was not covered by the existing JWT security tests and thus wasn’t spotted earlier.