Verify JWT signatures before trusting claims
JWT parsing must use a verification key and must not disable signature validation.
#Metadata
#Why it matters
Trusting unverified JWTs allows attackers to forge tokens with arbitrary claims.
#Remediation
Pass a `DecodingKey` to `decode` and validate claims with a strict `Validation` configuration.
#Repository path
The generated metadata points to critiq-rules/libs/rules/catalog/rules/rust/rust.security.jwt-without-verification.rule.yaml.