Skip to content

Expiration for JWT #5

Description

@DrillSergeant

First of all: thanks for this package, we are starting to use this for the first time.

By reading the code, I assume the tokens will currently be valid forever:

https://github.com/firebase/php-jwt/blob/d2113d9b2e0e349796e72d2a63cf9319100382d2/src/JWT.php#L148 checks for a timestamp value in the payload-value "exp" which is not send by https://github.com/rfyio/JWT/blob/303b3cd17e4ba146fb00ddcfd0bbf0ae673b8c31/Classes/Security/Authentication/Factory/TokenFactory.php#L69

Do I miss something (maybe you tackled that in another way already)?

If it is really missing, I could open a PR for that, my idea would be to extend TokenFactory::getJsonWebToken to add the key "exp" to the payload by using the current timestamp + expirationTime (new setting). Of course if $account->getExpirationDate()->getTimestamp() is smaller this will be used instead of the calculated exp.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions