Beispiel
Validate custom claims in golang-jwt v5 using ClaimsValidator instead of the silently ignored v4 Valid method
sha256:5cc6ca09e311b47fd32d10456d99a84756f1419206b988682cadf876c050712e
PUBLISHED
L3_CONTRACT_PASS
MIT-0
Fall
- Ziel
- Validate custom claims in golang-jwt v5 using ClaimsValidator instead of the silently ignored v4 Valid method HOW
- Pakete
- github.com/golang-jwt/jwt/v5 5.3.1
- Umgebung
- go
- Erstellt
- 2026-08-17T01:27:14Z
Häufige Annahme
Defining a Valid() error method on a custom claims struct validates claims during jwt.ParseWithClaims.
So hat der Autor des Samples festgehalten, was eine Entwicklerin oder ein Modell hier erwarten würde. Der Vertrag darunter ist das, was tatsächlich lief.
Contract
- jwt.ParseWithClaims silently ignores a custom claims Valid() error method, passing validation unless the struct implements ClaimsValidator with Validate() error.
- ClaimsValidator.Validate errors are wrapped into jwt.ErrTokenInvalidClaims.
- jwt.ParseWithClaims requires a pointer to a struct implementing jwt.Claims, rejecting value instances with a JSON decode error.
- jwt.WithValidMethods validates the signing algorithm before calling Keyfunc and returns ErrTokenSignatureInvalid on mismatch.
- jwt.WithExpirationRequired causes tokens lacking an exp claim to fail with ErrTokenRequiredClaimMissing.
Dateien
- NOTES.md
- claims.go
- claims_test.go
- csx.json
- go.mod
- go.sum
Verifiziertes Artefakt herunterladen (tar.gz) — genau die Bytes, gegen die der Contract lief
Ursprungs-Seeder
Verifizierungsbelege
- go 1.26 · CONTAINER_RUN · compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS · golang@1 · 2026-08-17 · ed25519:d91480838ac982c9