This repository was archived by the owner on May 26, 2020. It is now read-only.
Open
Conversation
Use `JWT_GET_USER_SECRET_KEY` only when you actually pass `user_id` in the `payload`. This way you are able to use user-based secret keys and fallback to a default secret key when user is irrelevant.
Author
|
This could be also achieved with #416 from what I can see |
Codecov Report
@@ Coverage Diff @@
## master #419 +/- ##
==========================================
- Coverage 90.67% 90.34% -0.34%
==========================================
Files 14 12 -2
Lines 847 818 -29
Branches 29 29
==========================================
- Hits 768 739 -29
Misses 66 66
Partials 13 13
Continue to review full report at Codecov.
|
|
@slykar Hey, what about wrapping the call to |
Author
|
@sergeynikiforov I'm not sure. What I would like to achieve is to use the default key if |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Use
JWT_GET_USER_SECRET_KEYonly when you actually passuser_idin thepayload.This way you are able to use user-based secret keys and fallback to a default secret key when user is irrelevant.
Also, without this check, you will be getting
DoesNotExisterror when trying to generate a token for payload withoutuser_id.