mirror of
https://github.com/steveiliop56/tinyauth.git
synced 2026-04-20 04:28:15 +00:00
ef157ae9ba
The validateAccessToken method was only decoding the JWT payload without verifying the signature, allowing attackers to forge tokens. This fix: - Adds ValidateAccessToken method to OIDCService that properly verifies JWT signature using RSA public key - Validates issuer, expiration, and required claims - Updates controller to use the secure validation method - Removes insecure manual JWT parsing code