Check JWT before deserializing request
michaelsproul opened this issue · comments
Eleel allows quite large amounts of data to be uploaded. We should check that the JWT token is verified before deserializing this data as JSON. Presently we're just using Axum's handler to get access to both the header and the JSON body, meaning we check the token after deserialization:
Lines 100 to 104 in 10e4ff2