PyCQA / PyCQA/bandit

Add plugin to check for insecure usage of jwt

Open
#799 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

enhancement
Dominant language
Python
Stars
8.3k
Forks
835
Avg merge
5d 3h
Merged PRs (30d)
1

Description

Is your feature request related to a problem? Please describe.
The documentation of PyJWT warns about various insecure usage of the module. It would be
great to incorporate checks into bandit for it.

https://pyjwt.readthedocs.io/en/stable/api.html

Describe the solution you'd like
See https://pyjwt.readthedocs.io/en/stable/api.html and apply bandit checks.

Describe alternatives you've considered
n/a

Additional context
n/a

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing the linked PyJWT API documentation, focusing on the insecure usage warnings that should become Bandit checks. Then inspect Bandit's existing plugin structure and conventions for comparable checks. Done means the relevant JWT misuse cases are identified and covered by working Bandit checks with tests.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.