Malformed JWT masking options in credential rules are now discarded.
What's wrong with this entry?
Deny-mode credential masking rules now discard a decode value that is not "jwt", and discard maskClaims unless it is an array of strings, on top of the existing cleanup of the extract, no-match and duplicate-masking options.
maskClaims requires decode \u2014 without a decode format there is no token to read claims from. Set decode, or omit maskClaims.
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.236
macOS sandbox re-applies read and delete denials inside writable folders
Both mention sandbox
-
v2.1.236
Sandbox proxy no longer writes to sockets that have gone away
Both mention sandbox
-
v2.1.236
IPv6 hosts through the proxy
Both mention sandbox