Skip to content
Closed
Show file tree
Hide file tree
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Finish
  • Loading branch information
Kwstubbs committed Sep 14, 2023
commit 84359fe1a8523dd43e2ce5e6be8cef5a3a1510fc
4 changes: 4 additions & 0 deletions go/ql/lib/semmle/go/frameworks/JWT.qll
Original file line number Diff line number Diff line change
Expand Up @@ -6,14 +6,18 @@ import go
* Provides models of commonly used functions in common JWT packages.
*/
module JWT {
/** Gets the package name `github.com/lestrrat-go/jwx` v2. */
string packageLestrrat() { result = package("github.com/lestrrat-go/jwx/v2/jwt", "") }
Comment thread
Kwstubbs marked this conversation as resolved.

/** Gets the package name `github.com/lestrrat-go/jwx` v1. */
string packageLestrratv1() { result = package("github.com/lestrrat-go/jwx/jwt", "") }
Comment thread
Kwstubbs marked this conversation as resolved.

/** Gets the package name `github.com/golang-jwt/jwt` v4 and v5. */
string packagePathModern() {
result = package(["github.com/golang-jwt/jwt/v5", "github.com/golang-jwt/jwt/v4"], "")
Comment thread
Kwstubbs marked this conversation as resolved.
}

/** Gets the package name `github.com/golang-jwt/jwt` v1 */
string packagePathOld() { result = package("github.com/golang-jwt/jwt", "") }

/**
Expand Down
5 changes: 5 additions & 0 deletions go/ql/src/change-notes/2023-09-13-JWT-signature-queries.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
category: newQuery
---
* Added JWT Confusion query `go/jwt-alg-confusion`
* Added JWT Parsing without Signature Check query `go/jwt-insecure-signing`
Comment thread
Kwstubbs marked this conversation as resolved.
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ import (
"github.com/lestrrat-go/jwx/v2/jwt"
)

func ExampleJWT_Parse() {
func ExampleJWT_Parse2() {
jwkSymmetricKey, _ := jwk.FromRaw([]byte(`abracadabra`))
tok, err := jwt.NewBuilder().
Issuer(`github.com/lestrrat-go/jwx`).
Expand All @@ -35,6 +35,3 @@ func ExampleJWT_Parse() {
_ = tok
// OUTPUT:
}
func main() {
ExampleJWT_Parse()
}
Original file line number Diff line number Diff line change
Expand Up @@ -37,6 +37,3 @@ func ExampleJWT_Parse() {
_ = tok
// OUTPUT:
}
func main() {
ExampleJWT_Parse()
}