Files
windmill/backend/windmill-common/tests
5095456bb6 chore(security): bump jsonwebtoken to 10 (#11194)
* refactor(jwt): route JWK algorithm lookup through one helper

Add `windmill_common::jwt::jwk_algorithm` as the single place that reads a
JWK's `alg`, and make `guest_jwt::jwk_algorithms` use it. EE code will call
the same helper, so the upcoming jsonwebtoken bump (which renames the field
to `key_algorithm: Option<KeyAlgorithm>`) only has to touch the helper's body.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* chore(security): bump jsonwebtoken to 10

Resolves dependency alerts 193 and 344 (jsonwebtoken) and, for the
windmill-parser-wasm lock, 341 (ring 0.16).

- jsonwebtoken 8.3.0 -> 10.4.0 with the `rust_crypto` backend (10.x has no
  default crypto backend). `jwk_algorithm` now reads `key_algorithm` (a
  `KeyAlgorithm`, signing and encryption algorithms alike) and maps only the
  signing subset onto `Algorithm`; `guest_jwt::jwk_algorithms` refuses a key
  naming a non-signing `alg` (RSA-OAEP, ...) instead of treating it as
  alg-less. `decode_without_verify` moves off the removed
  `insecure_disable_signature_validation` onto `dangerous::insecure_decode`.
- Workspace lock: only jsonwebtoken and `pem 1.1.1` (removed) change; the
  rust_crypto tree was already present. `ring 0.16.20` stays in
  backend/Cargo.lock because `gcp_auth 0.9.0` holds it.
- windmill-parser-wasm lock: jsonwebtoken 8.3.0 -> 10.4.0 drops `ring 0.16.20`
  (jsonwebtoken was its only holder there), `spin 0.5.2`, `untrusted 0.7.1`,
  `base64 0.13.1`; `pem 1.1.1 -> 3.0.6` and `serde_json 1.0.143 -> 1.0.151`
  were forced by the new jsonwebtoken.
- ee-repo-ref.txt -> 514eb5f5 (windmill-ee-private chore/ee-dep-bumps, on top
  of the previous ref d252afcc), which reads the JWK algorithm through
  `windmill_common::jwt::jwk_algorithm` and builds proto `KeyValue`s with
  `..Default::default()`.

The opentelemetry 0.32 bump is deferred: tracing-opentelemetry 0.33 removed
`OtelData`/`PreSampledTracer`, which the EE `otel_ee.rs` log bridge uses, and
`otel` ships in every EE image (`ee_core`); that bridge needs a
`Dispatch`-based rewrite first.

Checks (SQLX_OFFLINE, EE files from 514eb5f5): cargo check --features
all_sqlx_features; --features all_sqlx_features,private; --features
enterprise,private,otel; cargo test -p windmill-common --lib jwt (22 passed).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(jwt): keep audience-bearing tokens and 8192-bit RSA keys working on jsonwebtoken 10

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* chore: update ee-repo-ref to 6f3161192ab0eba36a8630b92e6765a36a3326fc

This commit updates the EE repository reference after PR #809 was merged in windmill-ee-private.

Previous ee-repo-ref: 7dcc5741c2fa9f9997b3da085f1f18ffc1e446d6

New ee-repo-ref: 6f3161192ab0eba36a8630b92e6765a36a3326fc

Automated by sync-ee-ref workflow.

---------

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Co-authored-by: windmill-internal-app[bot] <windmill-internal-app[bot]@users.noreply.github.com>
Co-authored-by: Ruben Fiszel <ruben@windmill.dev>
2026-09-21 14:36:03 +00:00
..