mirror of
https://github.com/windmill-labs/windmill.git
synced 2026-10-03 16:02:12 +00:00
* refactor(jwt): route JWK algorithm lookup through one helper Add `windmill_common::jwt::jwk_algorithm` as the single place that reads a JWK's `alg`, and make `guest_jwt::jwk_algorithms` use it. EE code will call the same helper, so the upcoming jsonwebtoken bump (which renames the field to `key_algorithm: Option<KeyAlgorithm>`) only has to touch the helper's body. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * chore(security): bump jsonwebtoken to 10 Resolves dependency alerts 193 and 344 (jsonwebtoken) and, for the windmill-parser-wasm lock, 341 (ring 0.16). - jsonwebtoken 8.3.0 -> 10.4.0 with the `rust_crypto` backend (10.x has no default crypto backend). `jwk_algorithm` now reads `key_algorithm` (a `KeyAlgorithm`, signing and encryption algorithms alike) and maps only the signing subset onto `Algorithm`; `guest_jwt::jwk_algorithms` refuses a key naming a non-signing `alg` (RSA-OAEP, ...) instead of treating it as alg-less. `decode_without_verify` moves off the removed `insecure_disable_signature_validation` onto `dangerous::insecure_decode`. - Workspace lock: only jsonwebtoken and `pem 1.1.1` (removed) change; the rust_crypto tree was already present. `ring 0.16.20` stays in backend/Cargo.lock because `gcp_auth 0.9.0` holds it. - windmill-parser-wasm lock: jsonwebtoken 8.3.0 -> 10.4.0 drops `ring 0.16.20` (jsonwebtoken was its only holder there), `spin 0.5.2`, `untrusted 0.7.1`, `base64 0.13.1`; `pem 1.1.1 -> 3.0.6` and `serde_json 1.0.143 -> 1.0.151` were forced by the new jsonwebtoken. - ee-repo-ref.txt -> 514eb5f5 (windmill-ee-private chore/ee-dep-bumps, on top of the previous ref d252afcc), which reads the JWK algorithm through `windmill_common::jwt::jwk_algorithm` and builds proto `KeyValue`s with `..Default::default()`. The opentelemetry 0.32 bump is deferred: tracing-opentelemetry 0.33 removed `OtelData`/`PreSampledTracer`, which the EE `otel_ee.rs` log bridge uses, and `otel` ships in every EE image (`ee_core`); that bridge needs a `Dispatch`-based rewrite first. Checks (SQLX_OFFLINE, EE files from 514eb5f5): cargo check --features all_sqlx_features; --features all_sqlx_features,private; --features enterprise,private,otel; cargo test -p windmill-common --lib jwt (22 passed). Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * fix(jwt): keep audience-bearing tokens and 8192-bit RSA keys working on jsonwebtoken 10 Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * chore: update ee-repo-ref to 6f3161192ab0eba36a8630b92e6765a36a3326fc This commit updates the EE repository reference after PR #809 was merged in windmill-ee-private. Previous ee-repo-ref: 7dcc5741c2fa9f9997b3da085f1f18ffc1e446d6 New ee-repo-ref: 6f3161192ab0eba36a8630b92e6765a36a3326fc Automated by sync-ee-ref workflow. --------- Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com> Co-authored-by: windmill-internal-app[bot] <windmill-internal-app[bot]@users.noreply.github.com> Co-authored-by: Ruben Fiszel <ruben@windmill.dev>