Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

jwt签名内容包含了用户的密码,签名只可验证不能保密,会泄漏密码,只包含用户id就好了吧 #128

Open
wangyongfeng5 opened this issue Jul 20, 2021 · 2 comments

Comments

@wangyongfeng5
Copy link

No description provided.

@1-bytes
Copy link

1-bytes commented Nov 15, 2021

是的,看到将用户名和密码的信息摘要写了进去,后来我用的时候又改写的
其实只存储 uid 和 username 就可以了,完全没必要再将密码的哈希存储区进去

@whzywxt
Copy link

whzywxt commented Feb 21, 2023

我自己简单改了下,只存username,去掉password,有效期改为配置项了。

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants