JWT / session tokens
The payload is a claim list. The header is the attack. Verify what the server actually verifies.
Tags: jwt, ato, session
Checklist
- Decode, do not trust: alg, kid, jku, x5u, typ, cty. iss/aud/exp/nbf/iat. role, tenant, email, email_verified.
- alg confusion: none / None, RS256 to HS256 with the published PEM as HMAC secret. Server must accept it, not just decode.
- kid / jku: Path, SQL, URL fetch. jku/x5u is SSRF plus a key you control.
- Claim tamper: role, tenant_id, user_id, email_verified. Unsigned or weakly signed tokens only.
- Refresh vs access: Logout must kill refresh. Rotation. Reuse detection.
- Storage: localStorage XSS, parent-domain cookie, mobile WebView leak.