]> git.ipfire.org Git - thirdparty/dovecot/core.git/commitdiff
lib-oauth2: test-oauth2-jwt - Ensure we ignore 'none' algorithm
authorAki Tuomi <aki.tuomi@open-xchange.com>
Thu, 28 May 2020 12:05:08 +0000 (15:05 +0300)
committerDovecot Automation <automation@dovecot.org>
Wed, 14 Jun 2023 07:03:29 +0000 (07:03 +0000)
src/lib-oauth2/test-oauth2-jwt.c

index 890712e48dcb9860003ff5417c128ddf93447faa..5f9925c27610672c6c4b474afb627c7b8a95c005 100644 (file)
@@ -430,6 +430,11 @@ static void test_jwt_broken_token(void)
                                 "q2wwwWWJVJxqw-J3uQ0DdlIyWfoZ7Z0QrdzvMW_B-jo",
                        .is_jwt = TRUE
                },
+               { /* algorithm is 'none' */
+                       .token = "eyJhbGciOiJub25lIiwidHlwIjoiSldUIn0."
+                                "eyJleHAiOjE1ODEzMzA3OTN9.",
+                       .is_jwt = TRUE
+               }
        };
 
        test_begin("JWT broken tokens");