The public key decoding from JWKS was missing base64url padding, causing JWT signature verification to fail with "invalid jwt token" errors in production. The `jwk.x` value needs proper padding before base64 decoding. Fixed by using the existing `base64urlDecode` helper function which correctly adds padding, instead of manually doing the conversion. This resolves JWT verification failures when REQUIRE_SIGNED_DEBUG_REQUESTS is enabled. Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
33 KiB
33 KiB