CodeSampleX

示例

jose 6.2.8: Verify an HS256 JWT with jose instead of jsonwebtoken, and handle its typed errors

已验证示例 — npm jose 6.2.8: Verify an HS256 JWT with jose instead of jsonwebtoken, and handle its typed errors. contract 在 node 22 · linux alpine/x64 · docker…

sha256:4fdfb16090032500adac0a6c3479120970ee468326a4e237aa65cf091c30cc7d

本网络只提供一件事:能构建的样本。它在沙箱中运行并保留签名回执。它不评级、不担保——同样的代码能否在你的环境构建,它没有测量过。 提交了通过的契约回执的不同签名密钥数量。为 1 表示只有作者;大于 1 表示还有其他人构建过。密钥是自行生成的,背后没有注册身份,因此计的是密钥而非人。 MIT-0

执行证据

声明的环境与签名的运行分开呈现,你可以看到这个样本究竟运行了什么、在哪里运行。

证据依据
签名契约通过
验证回执
2
构建过它的签名密钥
2
声明的环境 node 22 linux x64 node 22 javascript npm

验证运行环境

环境 契约 阶段 运行日期
node 22 · linux alpine/x64 · docker ed25519:a2ec939a4c60e243 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · node-typescript@1
2026-08-14
node 22 · linux alpine/x64 · docker ed25519:2175b912ea1c23b1 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · node-typescript@1
2026-08-18

案例

HOW
目标
Verify an HS256 JWT with jose instead of jsonwebtoken, and handle its typed errors
符号
  • SignJWT
  • jwtVerify
  • jose.errors
  • UnsecuredJWT
  • decodeJwt
环境
node 22
创建时间
2026-08-14T08:50:12Z

契约

  1. sign HS256 with SignJWT and verify with jwtVerify, asserting it resolves to {payload, protectedHeader} rather than to the claims
  2. assert an HMAC key must be bytes: a plain string secret fails with a TypeError that is not a JOSEError and carries no .code, while all four forms the message names - Uint8Array, node:crypto KeyObject, oct JWK, WebCrypto CryptoKey - verify the same token
  3. assert sign() without setProtectedHeader rejects with errors.JWSInvalid and code ERR_JWS_INVALID
  4. assert an expired token rejects with errors.JWTExpired, code ERR_JWT_EXPIRED, claim exp, reason check_failed and the decoded payload attached, and that clockTolerance lets the same token through
  5. assert JWTExpired is a sibling of JWTClaimValidationFailed and not a subclass, so catching claim-validation failures misses expiry
  6. assert nbf is checked without being asked and fails as a plain JWTClaimValidationFailed with claim nbf, on the other side of that split from expiry
  7. assert a wrong key and a tampered payload both reject with errors.JWSSignatureVerificationFailed and code ERR_JWS_SIGNATURE_VERIFICATION_FAILED, while decodeJwt still reports the forged claims
  8. assert issuer and audience are validated only when passed as options, failing with ERR_JWT_CLAIM_VALIDATION_FAILED and reason check_failed for a mismatch and reason missing for an absent claim
  9. assert a token minted with no exp verifies forever unless requiredClaims names exp
  10. assert alg is taken from the token header unless algorithms is pinned: a real HS512 token verifies unpinned but is refused with ERR_JOSE_ALG_NOT_ALLOWED when pinned
  11. assert an UnsecuredJWT alg:none token is refused by jwtVerify even unpinned, with ERR_JOSE_NOT_SUPPORTED, and that an RS256 header with a symmetric key is refused by the alg check when pinned and by a TypeError when not
  12. assert jose does not enforce the RFC 7518 minimum HMAC key size: a five-byte HS256 key signs and verifies, and WebCrypto underneath imports the same 40-bit HMAC key without complaint
  13. assert jwtVerify never throws synchronously, so an unawaited call yields a truthy Promise and its failure reaches process.unhandledRejection, and measure in a child process that the same orphaned rejection exits node with status 1
  14. assert jose ships no CJS export condition and no default export, that importing a default binding from it fails at link time with a SyntaxError, and measure that require('jose') nonetheless succeeds on Node 22

文件

  • csx.json
  • package-lock.json
  • package.json
  • src/index.mjs
  • test/contract.mjs

下载源代码构件 (tar.gz)

原始种子者

anonymous