Commit d2b0f9f
committed
jwt issue example: require input data, lowercase roles
If content-type is not supplied, input data will not be parsed. As a
result the JWT has the user's assigned roles. Prevent this.
Also lowercase all roles supplied in the input payload so "User", "user"
and "useR" all match the case insensitive "user" role.1 parent 5b67ace commit d2b0f9f
1 file changed
+8
-1
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1857 | 1857 | | |
1858 | 1858 | | |
1859 | 1859 | | |
| 1860 | + | |
| 1861 | + | |
1860 | 1862 | | |
1861 | 1863 | | |
1862 | 1864 | | |
| |||
1879 | 1881 | | |
1880 | 1882 | | |
1881 | 1883 | | |
| 1884 | + | |
| 1885 | + | |
| 1886 | + | |
| 1887 | + | |
| 1888 | + | |
1882 | 1889 | | |
1883 | 1890 | | |
1884 | 1891 | | |
| |||
1910 | 1917 | | |
1911 | 1918 | | |
1912 | 1919 | | |
1913 | | - | |
| 1920 | + | |
1914 | 1921 | | |
1915 | 1922 | | |
1916 | 1923 | | |
| |||
0 commit comments