Verifies a JWT's HMAC signature and returns its payload claims as a struct. Throws when the token is malformed, the signature does not match, the token's algorithm does not match the expected algorithm (when one is given, guarding against algorithm-substitution attacks), or the token is expired (exp) or not yet valid (nbf). Only HMAC algorithms are supported: HS256, HS384 and HS512. This is the Lucee crypto-extension name; RustCFML does not provide the Adobe verifySignedJWT name.
jwtVerify(token, key [, algorithm])
→ returns struct
HS256HS384HS512Sign a token and verify it back.
token = jwtSign({ sub: "alex" }, "my-secret", "HS256", 3600);
claims = jwtVerify(token, "my-secret");
writeDump(claims.sub);
Expected Result: alex
A signature check with the wrong secret throws.
token = jwtSign({ sub: "alex" }, "my-secret");
try {
jwtVerify(token, "other-secret");
} catch (any e) {
writeDump(e.getMessage());
}
Expected Result: JwtVerify: signature verification failed.
Signup for cfbreak to stay updated on the latest news from the ColdFusion / CFML community. One email, every friday.