A Flask application that issues JSON Web Tokens at /auth and reads them at /protected. When the token header names the NONE algorithm, the signature is not checked.
Pas commencéDockercommit ada0a80x86_64 · aarch64Secret
Forge an unsigned token to act as the admin user (JWT none algorithm). The demo account is user/user.
Le brief de ce lab se trouve dans son dépôt.