Skip to content

Commit 3916737

Browse files
committed
fix(azuread): turn on signature verification on JWT
There is no known reason for this to be turned off. In case this breaks some workflows, these should be fixed and not generally disabling the verification.
1 parent 5a0f060 commit 3916737

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

social_core/backends/azuread.py

+1-1
Original file line numberDiff line numberDiff line change
@@ -105,7 +105,7 @@ def user_data(self, access_token, *args, **kwargs):
105105
id_token = access_token
106106

107107
try:
108-
decoded_id_token = jwt.decode(id_token, options={"verify_signature": False})
108+
decoded_id_token = jwt.decode(id_token)
109109
except (jwt.DecodeError, jwt.ExpiredSignatureError) as de:
110110
raise AuthTokenError(self, de)
111111
return decoded_id_token

0 commit comments

Comments
 (0)