Repository navigation
[Server] Pad EC key coordinates in the JWKS test fixture - #558
Merged
chr-hertel merged 1 commit intoOct 8, 2026
Merged
Conversation
OpenSSL returns P-256 coordinates without leading zero bytes, so about 1 in 100 generated keys has a 31-byte x or y. RFC 7518 requires 32 bytes, and with the lowest dependencies the key is rejected and testFromIssuerTagsKeysWithoutAlgorithmPerToken fails. 🤖 Assisted with AI
mglaman
requested review from
CodeWithKyrian,
Nyholm,
chr-hertel and
soyuka
as code owners
October 8, 2026 00:26
chr-hertel
approved these changes
Oct 8, 2026
chr-hertel
left a comment
Member
There was a problem hiding this comment.
Ha, running into it right now as well - thanks!
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
testFromIssuerTagsKeysWithoutAlgorithmPerTokenfails about 1 run in 150. It failed bothunit (… lowest)jobs on #556, which doesn't touch OAuth.The test builds a P-256 JWK from
openssl_pkey_get_details(), which returnsxandywithout leading zero bytes. About 1% of generated keys have a 31-byte coordinate. RFC 7518 §6.2.1.2 requires the full 32 bytes. With--prefer-lowest(firebase/php-jwt7.0.0), the key is rejected, and the ES256 token is refused.The fixture now left-pads both coordinates:
Checked locally with lowest dependencies on PHP 8.5: 2 failures in 300 runs before, 0 in 600 after. In a separate script, 22 of 2,000 generated keys had a short coordinate.
🤖 Generated with Claude Code