Skip to content

Fix Date claims before the Unix epoch rounding toward zero - #813

Open
hossam1244 wants to merge 1 commit into
auth0:masterfrom
hossam1244:fix/806-date-claims-before-epoch
Open

hossam1244 wants to merge 1 commit into
auth0:masterfrom
hossam1244:fix/806-date-claims-before-epoch

Conversation

@hossam1244

Copy link
Copy Markdown

Changes

ClaimsSerializer.dateToSeconds serialized java.util.Date claims with truncating integer division (date.getTime() / 1000), so any date before the Unix epoch rounded toward zero and produced a later timestamp than the one set:

  • new Date(-500) → serialized as 0 (should be -1)
  • Instant.ofEpochMilli(-500) (same moment) → correctly serialized as -1

So the same instant silently produced different tokens depending on whether it was provided as a Date or an Instant.

The fix replaces the truncating division with Math.floorDiv(date.getTime(), 1000L), making the Date path agree with the existing Instant path (getEpochSecond(), which floors). Public API is unchanged; only the (incorrect) serialized output for pre-epoch dates changes.

Classes changed: com.auth0.jwt.impl.ClaimsSerializer (private static method), JWTCreatorTest (new tests).

References

Fixes #806

Testing

  • Added shouldAddExpiresAtBeforeEpochConsistentlyWithInstant: signs new Date(-500) and its equivalent Instant and asserts both serialize to {"exp":-1} and are identical to each other.
  • Added shouldAddNotBeforeBeforeEpoch: new Date(-500) → {"nbf":-1}.
  • Both tests fail on master and pass with this change; full :java-jwt:test suite passes (run on JDK 11, Gradle 6.9.2).

Date claims were serialized with truncating division, so any Date
before 1970-01-01T00:00:00Z serialized to the wrong (later) second:
new Date(-500) became 0 instead of -1, silently corrupting the claim.
Instant claims already floor correctly via getEpochSecond().

Use Math.floorDiv so both types agree on the boundary second.

Fixes auth0#806
@hossam1244
hossam1244 requested a review from a team as a code owner October 3, 2026 22:13

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Date claims before the Unix epoch are rounded toward zero

1 participant