I've developed a Connect app and starting today I'm getting the following errors in our middle tier server log:
com.atlassian.connect.spring.internal.jwt.JwtInvalidSigningAlgorithmException: Expected JWT to be signed with 'RS256' but it was signed with 'HS256' instead
at com.atlassian.connect.spring.internal.jwt.RsaJwtReader.getKeyIdAndCheckSigningAlgorithm(RsaJwtReader.java:48)
at com.atlassian.connect.spring.internal.auth.asymmetric.AsymmetricAuthenticationProvider.authenticate(AsymmetricAuthenticationProvider.java:57)
at org.springframework.security.authentication.ProviderManager.authenticate(ProviderManager.java:182)
at org.springframework.security.authentication.ProviderManager.authenticate(ProviderManager.java:201)
Are their recent changes to Atlassian's platform or SDK that would cause this? I've been developed my app for the last 12 months and this is the first tike I've seen this.
Also I see the error message:
com.atlassian.connect.spring.internal.auth.jwt.UnknownJwtIssuerException: Could not find an installed host for the provided client key: csrt-fake-token-ignore
This is being received from a known user. I understand thisis a security test by Atlassian but it's coming from one of my customer's cloud instance, ie, not an atlassian cloud account.
Any help is appreciated.