Add plugin to check for insecure usage of jwt
Nobody has claimed this yet.
- Dominant language
- Python
- Stars
- 8.3k
- Forks
- 835
- Avg merge
- 5d 3h
- Merged PRs (30d)
- 1
Description
Is your feature request related to a problem? Please describe.
The documentation of PyJWT warns about various insecure usage of the module. It would be
great to incorporate checks into bandit for it.
https://pyjwt.readthedocs.io/en/stable/api.html
Describe the solution you'd like
See https://pyjwt.readthedocs.io/en/stable/api.html and apply bandit checks.
Describe alternatives you've considered
n/a
Additional context
n/a
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reviewing the linked PyJWT API documentation, focusing on the insecure usage warnings that should become Bandit checks. Then inspect Bandit's existing plugin structure and conventions for comparable checks. Done means the relevant JWT misuse cases are identified and covered by working Bandit checks with tests.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- python
- Domain
- security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100