fix: close review findings on verification, flags, and output - #31
Merged
Merged
Conversation
- Reject JWS verification keys with no JWS algorithms (e.g. X25519) explicitly, so the alg allowlist fails closed instead of being skipped - Validate --color before --json forces color off, so a bad value errors under both output modes - Report an empty stdin pipe as "no token provided", matching the interactive prompt, instead of a malformed-token parse error - Resolve the JWE decryption key before printing any section, so an unusable key produces the error alone - Scan formatted JSON once in writeFormattedJSON Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GzPGnho3TkRuJx4sDpjajK
bsg62
force-pushed
the
fix/review-findings
branch
from
September 5, 2026 16:04
f182584 to
743c59a
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes the five findings from a codebase review. No behavior changes for well-formed inputs; each fix tightens an edge.
validMethodsForKeyreturns an empty list for unknown key types andverifyJWTSignaturerejects such a key outright ("key type cannot verify a JWS"). Previously an X25519 key (a valid JWE key, parseable via PKCS#8 or JWK) skipped the allowlist and relied on eachVerifyimplementation's type assertion to refuse it. AGENTS.md documents the rule.--coloris validated before--jsonis applied, so--json --color=boguserrors like the non-JSON path does.writeFormattedJSONscans the buffer once, delegating the fast-path decision to the escaper.Test plan
TestVerifyJWTSignature_RejectsKeyTypeWithoutJWSAlgorithms,TestReadToken_EmptyStdinPipe,TestDecodeAndPrintJWE_UnusableKeyPrintsNothing, plus a--jsoncase inTestApplyColorModego vet ./...,gofmt -l .,go test ./...pass--json --color=bogusand an empty pipe both exit 1 with the intended message🤖 Generated with Claude Code
https://claude.ai/code/session_01GzPGnho3TkRuJx4sDpjajK