Ejemplo
Enforce asymmetric key constraints including minimum RSA key size, EC named curve matching, and key roles
sha256:70b702f0bec4056d2b1d130f07f566fc2474c24141272abc15d93bb50ad32a34
PUBLISHED
L3_CONTRACT_PASS
MIT-0
Evidencia de ejecución
Separamos el entorno declarado de las ejecuciones firmadas para mostrar qué se demostró.
Base de evidenciaContrato firmado aprobado
Recibos de verificación1
Nivel de verificaciónL3_CONTRACT_PASS
Entorno declarado
- Contexto de ejecución
- node
- Sistema operativo
- linux
- Arquitectura
- x64
- Runtime
- node
- Lenguaje
- node
- Gestor de paquetes
- npm
Entornos de las ejecuciones de verificación
- Contexto de ejecución
- node 22
- Sistema operativo
- linux alpine · musl
- Arquitectura
- x64
- Runtime
- node 22
- Lenguaje
- javascript
- Gestor de paquetes
- npm
- Ejecución
- container · docker
CONTAINER_RUN · compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS · node-typescript@1 · 2026-08-17
Caso
- Objetivo
- Enforce asymmetric key constraints including minimum RSA key size, EC named curve matching, and key roles HOW
- Paquetes
-
jsonwebtoken 9.0.3
- Entorno
- node
- Creado
- 2026-08-17T20:01:32Z
Lo que suele suponerse
jwt.sign accepts any valid RSA key modulus and any elliptic curve key with ES256, and jwt.verify handles dynamic key resolver callbacks synchronously.
El autor de la muestra anotó aquí lo que un desarrollador o un modelo esperaría. El contrato de abajo es lo que realmente se ejecutó.
Contrato
- Signing with an RSA key with modulus under 2048 bits throws an error by default unless allowInsecureKeySizes is explicitly enabled.
- assert jwt.sign verifies EC curve compatibility and rejects P-384 keys when ES256 is specified
- assert jwt.sign rejects symmetric keys and public keys when an asymmetric algorithm like RS256 is specified
- assert jwt.verify with a key resolver callback throws when invoked synchronously and requires an asynchronous completion callback
- assert native KeyObject instances are accepted directly for asymmetric signing and verification without PEM string serialization
Archivos
- NOTES.md
- csx.json
- package-lock.json
- package.json
- src/index.mjs
- test/contract.mjs
Descargar el artefacto de código fuente (tar.gz)
Seeder de origen
csx-seed
Recibos de verificación
- node 22 · linux alpine/x64 · docker · CONTAINER_RUN · compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS · node-typescript@1 · 2026-08-17 · ed25519:d91480838ac982c9