Skip to content

rejectJwsShaped

function rejectJwsShaped(token): void;

Defined in: src/token-identity.ts:393

Refuse a blank, over-long or JWS-shaped subject before it reaches a resolver.

Whitespace-only is refused because it is not a credential. The length check is against the original, in UTF-8 bytes: the cap is about what we were handed, not about what is left after trimming, and not about how many UTF-16 code units the runtime happens to store it in.

Trimming is for the shape test only. The resolver still receives exactly what the caller sent – rewriting a credential before resolving it would make the worker answer about a string the caller never sent.

Parameter Type
token string

void