DSH Plugins
返回列表
🧩

dsh-tool-jwt

admin-security 更新于 2026.08.19

在终端中运行以下命令:

dsh plugin install chenxuhl/dsh-tool-jwt

将以下提示词粘贴到 DeepSeek Harness 对话框中:

在 DeepSeek Harness 中安装来自 https://github.com/chenxuhl/dsh-tool-jwt 的 JWT 工具插件,使用命令 dsh plugin install chenxuhl/dsh-tool-jwt 即可。

插件介绍

Working with JWTs in day-to-day backend work often means manually decoding base64url segments, hand-assembling header/payload/signature for test tokens, or trying to verify an HMAC in your head. dsh-tool-jwt collapses these chores into three deterministic actions. decode parses the header and payload into JSON and computes expiry status against the current clock without verifying the signature, making it ideal for a quick look at a token content. sign issues an HS256 token with automatic iat and optional exp. verify runs the full validation chain: it enforces alg=HS256, compares the signature with crypto.timingSafeEqual to resist timing attacks, and checks expiry with an optional leewaySeconds tolerance.

The plugin is a pure-function implementation with zero runtime dependencies, relying only on Node built-in crypto. Its security boundaries are deliberate: verify rejects alg=none and any non-HS256 algorithm to block downgrade attacks; token, secret, and payload are capped at 16KB, 4KB, and 8KB respectively and rejected at the entry point when exceeded; secret and secretBase64url are mutually exclusive, the latter supporting RFC 7515 binary key vectors and JWK k values. Signature correctness is verified byte-for-byte against the official HS256 test vectors in RFC 7515 Appendix A.1.

It is built for backend developers who regularly inspect, craft, or validate JWTs: debugging token content in staging or production, generating test credentials during integration testing, verifying gateway or downstream auth logic, or quickly demoing JWT structure in docs and teaching. It is not intended for production key management or high-throughput signing services; its role is a developer debugging tool, not a runtime component.

使用场景

  • 联调时为网关或下游服务快速签发测试 token
  • 拿到生产 token 后不验签快速查看 payload 与过期状态
  • 验证网关收到的 token 签名是否匹配、时效是否在容差内

适合人员

  • 日常处理 JWT 的后端开发者
  • 需要做联调造 token 的全栈工程师
  • 编写鉴权相关文档或教学内容的技术作者