[Bug] AuthLayer produces JWT with "exp" claim set to null
- Langage dominant
- Rust
- Étoiles
- 1.3k
- Forks
- 668
- Merge moyen
- 2 j 1 h
- PR mergées (30 j)
- 29
Description
### Component
transports
### What version of Alloy are you on?
2.0.5
### Operating System
None
### Describe the bug
AuthLayer inserts Authorization header with a JWT that is rejected as invalid by some execution clients (Besu). The reason is that the claim set in this JWT is serialized as `{"iat": , "exp": null}`: that is, instead of omitting `exp` claim, it is specified with `null` value.
Per RFC7519, §4.1.4, the value of `exp` claim must be a number.
Suggestion: set up serialization of `Claims` so that when `exp` has `None` value, it is omitted from the serialized representation.
Note also that Engine API specification does not specify the use of `exp`, it only uses `iat` for staleness detection; not sure why `exp` is included into the JWT used to authenticate Engine API.
Guide de contribution
Ouvrir le guide de contribution
Évaluation
Cette issue n'a pas encore été évaluée.