From 2f97402f43e4eab6a33b9082a44065abee1a8f87 Mon Sep 17 00:00:00 2001 From: pedrooot Date: Wed, 7 Oct 2026 17:45:53 +0200 Subject: [PATCH] docs(mcp): qualify the signature verification entry --- .../changelog.d/mcp-jwt-signature-verification.security.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/mcp_server/changelog.d/mcp-jwt-signature-verification.security.md b/mcp_server/changelog.d/mcp-jwt-signature-verification.security.md index 2df011cacc..8a4ccd4dbd 100644 --- a/mcp_server/changelog.d/mcp-jwt-signature-verification.security.md +++ b/mcp_server/changelog.d/mcp-jwt-signature-verification.security.md @@ -1 +1 @@ -JWT signatures in HTTP transport mode are verified against the Prowler API RS256 public key, supplied through DJANGO_TOKEN_VERIFYING_KEY or a file path, refusing forged, alg none and HMAC-keyed tokens +JWT signatures in HTTP transport mode are verified against the Prowler API RS256 public key when DJANGO_TOKEN_VERIFYING_KEY or its file path is configured, refusing forged, alg none and HMAC-keyed tokens, and falling back to the previous expiration-only check when neither is set