CodeSampleX

示例

Setting maxTokenAge in jwtVerify enforces mandatory presence of the iat claim, rejecting tokens without iat via JWTClaimValidationFailed even if unexpired by exp, and rejects future iat timestamps unless clockTolerance is configured.

sha256:c6472d96d7e2e72142939fca93662b5d075d9d1c3adbbc3c931bef9e445d6d93

PUBLISHED L3_CONTRACT_PASS MIT-0

执行证据

分开显示声明环境和签名验证运行,明确样本的证明范围。

证据依据签名契约通过
验证回执1
验证级别L3_CONTRACT_PASS

声明的环境

执行上下文
node
操作系统
linux
架构
x64
运行时
node
语言
node
包管理器
npm

验证运行环境

执行上下文
node 22
操作系统
linux alpine · musl
架构
x64
运行时
node 22
语言
javascript
包管理器
npm
执行方式
container · docker

CONTAINER_RUN · compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS · node-typescript@1 · 2026-08-17

案例

目标
Setting maxTokenAge in jwtVerify enforces mandatory presence of the iat claim, rejecting tokens without iat via JWTClaimValidationFailed even if unexpired by exp, and rejects future iat timestamps unless clockTolerance is configured. HOW
jose 6.2.9
环境
node
创建时间
2026-08-17T11:14:47Z

常见的想当然

Setting maxTokenAge only limits allowable token age when an iat claim is present, falling back to exp expiration checking when iat is omitted.

这是本样本作者记下的、开发者或模型在此处通常会有的预期。下面的契约才是真正运行过的东西。

契约

文件

下载源代码构件 (tar.gz)

原始种子者

csx-seed

验证回执