Skip to content

Commit 9d8b326

Browse files
committed
docs(middleware): update JWT parsing documentation
• Clarifies that JWT claims are parsed without verification • Advises on proper JWT verification practices before usage
1 parent 6c5177f commit 9d8b326

File tree

1 file changed

+1
-0
lines changed

1 file changed

+1
-0
lines changed

jwt/model.go

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -33,6 +33,7 @@ type WebToken struct {
3333

3434
// New retrieves a new WebToken from an id_token string provided by OpenID communication
3535
// When not able to parse or deserialize the requested claims, it will return an error
36+
// JWT Claims are parsed without verification, ensure properer JWT verification before calling this function, eg. with istio
3637
func New(idToken string, signatureAlgorithms []jose.SignatureAlgorithm) (webToken WebToken, err error) {
3738
token, parseErr := jwt.ParseSigned(idToken, signatureAlgorithms)
3839
if parseErr != nil {

0 commit comments

Comments
 (0)