CodeSampleX

サンプル

Setting maxTokenAge in jwtVerify enforces mandatory presence of the iat claim, rejecting tokens without iat via JWTClaimValidationFailed even if unexpired by exp, and rejects future iat timestamps unless clockTolerance is configured.

sha256:c6472d96d7e2e72142939fca93662b5d075d9d1c3adbbc3c931bef9e445d6d93

PUBLISHED L3_CONTRACT_PASS MIT-0

実行証拠

宣言環境と署名済み検証実行を分け、証明範囲を明確にします。

証拠の基準署名済みコントラクト合格
検証レシート1
検証レベルL3_CONTRACT_PASS

宣言された環境

実行コンテキスト
node
OS
linux
アーキテクチャ
x64
ランタイム
node
言語
node
パッケージマネージャー
npm

検証実行環境

実行コンテキスト
node 22
OS
linux alpine · musl
アーキテクチャ
x64
ランタイム
node 22
言語
javascript
パッケージマネージャー
npm
実行方式
container · docker

CONTAINER_RUN · compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS · node-typescript@1 · 2026-08-17

ケース

ゴール
Setting maxTokenAge in jwtVerify enforces mandatory presence of the iat claim, rejecting tokens without iat via JWTClaimValidationFailed even if unexpired by exp, and rejects future iat timestamps unless clockTolerance is configured. HOW
パッケージ
jose 6.2.9
環境
node
作成日
2026-08-17T11:14:47Z

よくある思い込み

Setting maxTokenAge only limits allowable token age when an iat claim is present, falling back to exp expiration checking when iat is omitted.

このサンプルの作者が、ここで開発者やモデルが期待するであろうこととして記録したもの。下の契約が実際に実行されたものだ。

コントラクト

ファイル

ソースアーティファクトをダウンロード (tar.gz)

オリジンシーダー

csx-seed

検証レシート