From 498e4a6ec24d2cd7e59f23a075ffd371a6a3f81b Mon Sep 17 00:00:00 2001 From: Jocelyn Fiat Date: Thu, 21 Sep 2017 10:46:08 +0200 Subject: [PATCH] Fixed validation of iss and aud when issuer and audience are not set. --- library/security/jwt/src/jwt.e | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/library/security/jwt/src/jwt.e b/library/security/jwt/src/jwt.e index f23091fb..acf1e3e0 100644 --- a/library/security/jwt/src/jwt.e +++ b/library/security/jwt/src/jwt.e @@ -59,6 +59,8 @@ feature -- Status report do if attached claimset.issuer as iss then Result := a_issuer = Void or else a_issuer.same_string (iss) + else + Result := a_issuer = Void end end @@ -66,6 +68,8 @@ feature -- Status report do if attached claimset.audience as aud then Result := a_audience = Void or else a_audience.same_string (aud) + else + Result := a_audience = Void end end