Skip to content

Update Type Validation Defaults #17181

Closed
Closed
@jzheaux

Description

@jzheaux

Related to #16672, Spring Security 7 should validate the JWT typ header by default instead of delegating that to Nimbus.

Metadata

Metadata

Assignees

Labels

in: oauth2An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)type: enhancementA general enhancement

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions