サンプル
jose 6.2.8: Verify an HS256 JWT with jose instead of jsonwebtoken, and handle its typed errors
検証済みサンプル — npm jose 6.2.8: Verify an HS256 JWT with jose instead of jsonwebtoken, and handle its typed errors. node 22 · linux alpine/x64 · docker で contract…
sha256:4fdfb16090032500adac0a6c3479120970ee468326a4e237aa65cf091c30cc7d
このネットワークが提供するのは一つだけです。ビルドされるサンプル。サンドボックスで実行し、署名済みの受領証を保管します。等級はつけず、何も保証しません — 同じコードがあなたの環境でビルドされるかは測定していません。
合格した契約受領証を提出した異なる署名鍵の数です。1 なら作者だけ、2 以上なら他の誰かもビルドしています。鍵は自己生成で背後に登録された身元がないため、数えているのは人ではなく鍵です。
MIT-0
実行証拠
宣言された環境と署名済みの実行を分けてあります。このサンプルが何をどこで実行したかをそのまま確認できます。
- 証拠の基準
- 署名済みコントラクト合格
- 検証レシート
- 2
- ビルドした署名鍵
- 2
宣言された環境
node 22 linux x64 node 22 javascript npm
検証実行環境
| 環境 | コントラクト | ステージ | 実行日 |
|---|---|---|---|
| node 22 · linux alpine/x64 · docker ed25519:a2ec939a4c60e243 | PASS | compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS CONTAINER_RUN · node-typescript@1 |
2026-08-14 |
| node 22 · linux alpine/x64 · docker ed25519:2175b912ea1c23b1 | PASS | compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS CONTAINER_RUN · node-typescript@1 |
2026-08-18 |
ケース
HOW- ゴール
- Verify an HS256 JWT with jose instead of jsonwebtoken, and handle its typed errors
- パッケージ
- シンボル
-
- SignJWT
- jwtVerify
- jose.errors
- UnsecuredJWT
- decodeJwt
- 環境
- node 22
- 作成日
- 2026-08-14T08:50:12Z
コントラクト
- sign HS256 with SignJWT and verify with jwtVerify, asserting it resolves to {payload, protectedHeader} rather than to the claims
- assert an HMAC key must be bytes: a plain string secret fails with a TypeError that is not a JOSEError and carries no .code, while all four forms the message names - Uint8Array, node:crypto KeyObject, oct JWK, WebCrypto CryptoKey - verify the same token
- assert sign() without setProtectedHeader rejects with errors.JWSInvalid and code ERR_JWS_INVALID
- assert an expired token rejects with errors.JWTExpired, code ERR_JWT_EXPIRED, claim exp, reason check_failed and the decoded payload attached, and that clockTolerance lets the same token through
- assert JWTExpired is a sibling of JWTClaimValidationFailed and not a subclass, so catching claim-validation failures misses expiry
- assert nbf is checked without being asked and fails as a plain JWTClaimValidationFailed with claim nbf, on the other side of that split from expiry
- assert a wrong key and a tampered payload both reject with errors.JWSSignatureVerificationFailed and code ERR_JWS_SIGNATURE_VERIFICATION_FAILED, while decodeJwt still reports the forged claims
- assert issuer and audience are validated only when passed as options, failing with ERR_JWT_CLAIM_VALIDATION_FAILED and reason check_failed for a mismatch and reason missing for an absent claim
- assert a token minted with no exp verifies forever unless requiredClaims names exp
- assert alg is taken from the token header unless algorithms is pinned: a real HS512 token verifies unpinned but is refused with ERR_JOSE_ALG_NOT_ALLOWED when pinned
- assert an UnsecuredJWT alg:none token is refused by jwtVerify even unpinned, with ERR_JOSE_NOT_SUPPORTED, and that an RS256 header with a symmetric key is refused by the alg check when pinned and by a TypeError when not
- assert jose does not enforce the RFC 7518 minimum HMAC key size: a five-byte HS256 key signs and verifies, and WebCrypto underneath imports the same 40-bit HMAC key without complaint
- assert jwtVerify never throws synchronously, so an unawaited call yields a truthy Promise and its failure reaches process.unhandledRejection, and measure in a child process that the same orphaned rejection exits node with status 1
- assert jose ships no CJS export condition and no default export, that importing a default binding from it fails at link time with a SyntaxError, and measure that require('jose') nonetheless succeeds on Node 22
ファイル
- csx.json
- package-lock.json
- package.json
- src/index.mjs
- test/contract.mjs