Sfoglia il codice sorgente

Call `jwt.decode` with the expected algorithms

Tim Farrell 1 anno fa
parent
commit
4fceb404bd
1 ha cambiato i file con 1 aggiunte e 1 eliminazioni
  1. 1 1
      backend/utils/utils.py

+ 1 - 1
backend/utils/utils.py

@@ -48,7 +48,7 @@ def create_token(data: dict, expires_delta: Union[timedelta, None] = None) -> st
 
 def decode_token(token: str) -> Optional[dict]:
     try:
-        decoded = jwt.decode(token, SESSION_SECRET)
+        decoded = jwt.decode(token, SESSION_SECRET, algorithms=[ALGORITHM])
         return decoded
     except Exception as e:
         return None