verify audience in jwt
This commit is contained in:
parent
ae6dfb2644
commit
424273360d
|
@ -193,7 +193,6 @@ def gen_token(auth):
|
||||||
'iss': issuer,
|
'iss': issuer,
|
||||||
'aud': audience
|
'aud': audience
|
||||||
}
|
}
|
||||||
|
|
||||||
token = jwt.encode(payload, secret, algorithm='HS256')
|
token = jwt.encode(payload, secret, algorithm='HS256')
|
||||||
return token
|
return token
|
||||||
|
|
||||||
|
@ -210,8 +209,7 @@ def access_token(request):
|
||||||
token = jwt.encode(decoded, secret, algorithm='HS256')
|
token = jwt.encode(decoded, secret, algorithm='HS256')
|
||||||
return Response(text=str(token.decode('utf-8')))
|
return Response(text=str(token.decode('utf-8')))
|
||||||
else:
|
else:
|
||||||
return HTTPUnauthorized(reason='Token could not be refreshed')
|
return HTTPUnauthorized(reason='Token could not be verified')
|
||||||
return True
|
|
||||||
|
|
||||||
def verify_token(token):
|
def verify_token(token):
|
||||||
secret = get_config()['jwt']['secret']
|
secret = get_config()['jwt']['secret']
|
||||||
|
|
Loading…
Reference in New Issue