fix(jwt): we follow the spec now
janl committed Nov 1, 2021
1 parent 281ad9f commit 1c3f87022077ba3a8bc83a84af0e8a579bf5b632
Showing 1 changed file with 1 addition and 2 deletions.
@@ -379,8 +379,7 @@ Additionally, CouchDB can be configured to reject JWT tokens that are
missing a configurable set of claims (e.g, a CouchDB administrator
could insist on the ``exp`` claim).

All claims presented in a JWT token are validated if presented, regardless of whether they
are required.
Only claims listed in required checks are validated. Additional claims will be ignored.

Two sections of config exist to configure JWT authentication;

