We should verify signatures to make the whole session secret meaningful.

This commit is contained in:
Tim Farrell 2024-02-01 13:46:45 -06:00
parent 03a7e35967
commit 2c1dacb9b6

View File

@ -48,7 +48,7 @@ def create_token(data: dict, expires_delta: Union[timedelta, None] = None) -> st
def decode_token(token: str) -> Optional[dict]:
try:
decoded = jwt.decode(token, SESSION_SECRET, options={"verify_signature": False})
decoded = jwt.decode(token, SESSION_SECRET)
return decoded
except Exception as e:
return None