The OpenID Connect discovery document advertises "none" among its id_token_signing_alg_values_supported, meaning the authorization server is willing to issue ID tokens with no signature. A relying party that accepts such a token cannot verify its integrity, enabling JWT "alg:none" forgery and authentication bypass. The "none" algorithm should never be offered for ID tokens in production.
登录后查看神龙缓存的 POC 文件快照
登录查看