|Aydin Mercan 89cb6ced09||5 months ago|
|.github/workflows||7 months ago|
|internal/publickey||6 months ago|
|jwk||6 months ago|
|.woodpecker.yml||5 months ago|
|LICENSE||7 months ago|
|README.md||5 months ago|
|go.mod||6 months ago|
|go.sum||6 months ago|
Insecure library for a set of insecure formats. It aims to provide inflexible verification for cases where you unfortunately can't avoid touching JWT.
- Go >= 1.17
Don't use JWT. You don't need me to tell you about it. Likewise, you shouldn't need me to tell you that you shouldn't use this library.
- Just enough JWT for people to speak commonly encountered OAuth 2.0 (esp. with OIDC) and alike.
- Don't allow for any of the sharp edges.
- Allow for binding domain parameters as much as possible to the public keys.
- Extensive test coverage even if a particular case seems pedantic, guaranteed to be handled properly and/or improbable to be problematic.
- Signing capabilities.
- Anything that has to do with encryption, key exchange or MACs.
- Be 100% compliant with the standard.
This repository is licensed under the
BSD-3-Clause. Refer to LICENSE for more information.