Skip to content

Conversation

@forivall
Copy link
Contributor

Companion to #24, tests for the current behaviour, since some dependents (jsonwebtoken) may already depend on this usage, and so #24 would be a breaking change.

If #24 won't be accepted, I'll update the docs in this PR so that users know to decode in a try/catch, since, if they don't, they could be vulnerable to a DOS attack.

@omsmith omsmith merged commit ff484ac into auth0:master Sep 5, 2016
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants