Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Default JWT secret #470

Closed
twobeeb opened this issue Oct 21, 2020 · 3 comments
Closed

Default JWT secret #470

twobeeb opened this issue Oct 21, 2020 · 3 comments
Labels
backend Need a backend update bug Something isn't working login Login & Acls on AKHQ

Comments

@twobeeb
Copy link
Contributor

twobeeb commented Oct 21, 2020

The default behavior when micronaut.security.token.jwt.signatures.secret.generator.secret is not set is to generate a JWT without signature, that lets anyone change its claim effortless.

I believe this is a security flaw and AKHQ should not even start if there is no secret, or at least there should be a default secret, along with a warning log at run time when the secret have not been changed.

@tchiotludo tchiotludo added backend Need a backend update bug Something isn't working login Login & Acls on AKHQ labels Oct 21, 2020
@tchiotludo
Copy link
Owner

I think Micronaut will crashed on this case, don't know if we need to report it to micronaut or handle it on akhq

@tchiotludo
Copy link
Owner

Got idea, I'll start like that :)
Thanks

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
backend Need a backend update bug Something isn't working login Login & Acls on AKHQ
Projects
Status: Done
Development

No branches or pull requests

2 participants