
Episode 376: Justin Richer On API Security with OAuth 2
Software Engineering Radio - the podcast for professional software developers
00:00
So You Could Sign a Jot With Base 64 URL Encoded JSON?
A signed Jot is three lots of base 64. If you saw on your screen, you'd see the three full stops when you're that separate. Even without access to libraries, you really only need string split. That doesn't give you signature validation, but it'll at least let you parse the payloads and headers. You have to be really careful about what you put in the token, because it's very easy to see it.
Transcript
Play full episode