What if someone used the correct case but weird Unicode characters? I mean, if "none" = "nonE", is "none" = "none"
The end result depends entirely on the behavior of JavaScript's Array.indexOf() implementation.
If Auth0 is doing any sort of normalization they will definitely be vulnerable to all the normalization bugs from unicode. Would be a great follow up vulnerability.
They are fine for human-visible names, but field names and internal enum values should use byte-by-byte comparison. It just makes entire class of vulnerabilities go away.
> The "alg" value is a case-sensitive ASCII string containing a StringOrURI value. This Header Parameter MUST be present and MUST be understood and processed by implementations.