Skip to content

Security Fix for jsonwebtoken Module#7

Merged
chris-sev merged 2 commits intoscotch-io:masterfrom
zinniacodes:securityfix
Mar 3, 2016
Merged

Security Fix for jsonwebtoken Module#7
chris-sev merged 2 commits intoscotch-io:masterfrom
zinniacodes:securityfix

Conversation

@zinniacodes
Copy link
Contributor

Updated package.json and updated the token expiry time parameter as the old parameter was deprecated in the new version of jsonwebtoken. New expiresIn is in seconds only.

See here for details on vulnerability: https://auth0.com/blog/2015/03/31/critical-vulnerabilities-in-json-web-token-libraries/

chris-sev pushed a commit that referenced this pull request Mar 3, 2016
Security Fix for `jsonwebtoken` Module
@chris-sev chris-sev merged commit 4869989 into scotch-io:master Mar 3, 2016
@chris-sev
Copy link
Member

Awesome. Thanks for the info and the fix.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants