Leakage of sensitive data in JWT
Overview
Description
Remediation Guidelines
const jwt = require('jsonwebtoken'); const token = jwt.sign({ user: { email: '[email protected]' }}); // unsafeconst jwt = require('jsonwebtoken'); const token = jwt.sign({ user: user.uuid });
References
Configuration
PreviousLeakage of sensitive data in exception messageNextLeakage of sensitive data in local storage
Last updated