Hacker News new | ask | show | jobs
by fuzzy2 2315 days ago
It means to allow only expected algorithms.

Because as critics rightfully point out, without any whitelisting, you can just specify that your JWT does not have a signature and then it’s a valid token, whatever the contents.