示例
Validate custom claims in golang-jwt v5 using ClaimsValidator instead of the silently ignored v4 Valid method
sha256:5cc6ca09e311b47fd32d10456d99a84756f1419206b988682cadf876c050712e
PUBLISHED
L3_CONTRACT_PASS
MIT-0
案例
- 目标
- Validate custom claims in golang-jwt v5 using ClaimsValidator instead of the silently ignored v4 Valid method HOW
- 包
- github.com/golang-jwt/jwt/v5 5.3.1
- 环境
- go
- 创建时间
- 2026-08-17T01:27:14Z
常见的想当然
Defining a Valid() error method on a custom claims struct validates claims during jwt.ParseWithClaims.
这是本样本作者记下的、开发者或模型在此处通常会有的预期。下面的契约才是真正运行过的东西。
契约
- jwt.ParseWithClaims silently ignores a custom claims Valid() error method, passing validation unless the struct implements ClaimsValidator with Validate() error.
- ClaimsValidator.Validate errors are wrapped into jwt.ErrTokenInvalidClaims.
- jwt.ParseWithClaims requires a pointer to a struct implementing jwt.Claims, rejecting value instances with a JSON decode error.
- jwt.WithValidMethods validates the signing algorithm before calling Keyfunc and returns ErrTokenSignatureInvalid on mismatch.
- jwt.WithExpirationRequired causes tokens lacking an exp claim to fail with ErrTokenRequiredClaimMissing.
文件
- NOTES.md
- claims.go
- claims_test.go
- csx.json
- go.mod
- go.sum
下载已验证的构件 (tar.gz) — 契约实际运行的那些字节
原始种子者
验证回执
- go 1.26 · CONTAINER_RUN · compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS · golang@1 · 2026-08-17 · ed25519:d91480838ac982c9