Skip to content

fix: use standard JWT expiry claims for image proxy - #200

Open
vlnst wants to merge 1 commit into
httpjamesm:mainfrom
vlnst:fix-jwt-expiry-claims
Open

vlnst wants to merge 1 commit into
httpjamesm:mainfrom
vlnst:fix-jwt-expiry-claims

Conversation

@vlnst

@vlnst vlnst commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

ImageProxyClaims declared its own iss/exp fields with the same JSON names as the standard ones in the embedded jwt.RegisteredClaims, so the standard fields stayed empty and the jwt library skipped the expiry check; only a manual check in routes/image.go did it.

This switches to the standard IssuedAt/ExpiresAt, lets ParseWithClaims enforce expiry, removes the manual check, and adds a test.

The test uses jwt.TimeFunc, which jwt v5 removed. If #198 is merged first, it needs jwt.WithTimeFunc instead.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant