Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Passive Test / JWT Security #70

Open
DeliciousBounty opened this issue Aug 31, 2022 · 4 comments
Open

Passive Test / JWT Security #70

DeliciousBounty opened this issue Aug 31, 2022 · 4 comments
Labels
New passive check New passive check

Comments

@DeliciousBounty
Copy link
Collaborator

We are looking for contributors!

JWT passive test will run several tests on the JWT Token in accordance with best practices.
In other words, ensure that the token's structure is legitimate, valid encryption, etc.
For more details please check OWASP:
https://owasp.org/www-chapter-belgium/assets/2021/2021-02-18/JWT-Security.pdf
https://cheatsheetseries.owasp.org/cheatsheets/JSON_Web_Token_for_Java_Cheat_Sheet.html

@DeliciousBounty DeliciousBounty added the New passive check New passive check label Sep 1, 2022
@GuyL99 GuyL99 added the bounty label Sep 4, 2022
@glokta1
Copy link

glokta1 commented Oct 2, 2022

Hi, I'd like to work on this issue.

@DeliciousBounty
Copy link
Collaborator Author

Hi @glokta1 Thank for getting involved,
Check the contribute.md .
If you need help or do you have any questions feel free to ask :)
This is my mail : [email protected]

@RazMag RazMag removed the bounty label Oct 25, 2022
@Hrushi20
Copy link

Hrushi20 commented Feb 25, 2023

Is the aim of the issue to write JWT passive tests to validate token's structure, valid encryption etc? Also, is the bounty still applicable?

@DeliciousBounty
Copy link
Collaborator Author

@Hrushi20 Yes exactly your suggestions can be included in this passive check , but actually there is no bounty.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
New passive check New passive check
Projects
None yet
Development

No branches or pull requests

5 participants