A Flask application that issues HS256 JSON Web Tokens at /auth and checks them at /protected. The signing secret is weak.
Not startedDockercommit 0b75c5cx86_64 · aarch64Secret
Crack the HMAC secret of the token you are issued, then sign a token that identifies you as another user (JWT weak secret).
The brief for this lab lives in its repository.