From 515001e9b566b76156b0b162d36a2a6901374ef6 Mon Sep 17 00:00:00 2001 From: Andriy Romanov Date: Thu, 30 Jul 2026 15:43:18 -0700 Subject: [PATCH] Allow jwt 3.x Relax the jwt runtime dependency from ~> 2 to >= 2, < 4 so consumers can upgrade to jwt 3.x. The lockfile now resolves jwt 3.2.0 so CI exercises the new major. The only spec change needed: jwt 3 decodes base64 strictly (RFC 4648), so the invalid-signature spec now tampers the signature with a valid base64 segment instead of appending raw characters. Co-Authored-By: Claude Fable 5 Co-Authored-By: Amplify 3.0.1 --- Gemfile | 2 +- Gemfile.lock | 6 +++--- omniauth-auth0.gemspec | 2 +- spec/omniauth/auth0/jwt_validator_spec.rb | 7 ++++++- 4 files changed, 11 insertions(+), 6 deletions(-) diff --git a/Gemfile b/Gemfile index 92041bb..a82fcdd 100644 --- a/Gemfile +++ b/Gemfile @@ -2,7 +2,7 @@ source 'https://rubygems.org' gemspec -gem 'jwt', '~> 2' +gem 'jwt', '>= 2', '< 4' gem 'rake', '~> 13' group :development do diff --git a/Gemfile.lock b/Gemfile.lock index 47100a4..118ae76 100644 --- a/Gemfile.lock +++ b/Gemfile.lock @@ -2,7 +2,7 @@ PATH remote: . specs: omniauth-auth0 (3.2.0) - jwt (~> 2) + jwt (>= 2, < 4) omniauth (~> 2) omniauth-oauth2 (~> 1) @@ -55,7 +55,7 @@ GEM logger io-console (0.8.2) json (2.19.5) - jwt (2.10.2) + jwt (3.2.0) base64 language_server-protocol (3.17.0.5) lint_roller (1.1.0) @@ -195,7 +195,7 @@ DEPENDENCIES bundler dotenv (~> 2) guard-rspec (~> 4) - jwt (~> 2) + jwt (>= 2, < 4) listen (~> 3) multi_json (~> 1) omniauth-auth0! diff --git a/omniauth-auth0.gemspec b/omniauth-auth0.gemspec index f4fc6fb..ebc811a 100644 --- a/omniauth-auth0.gemspec +++ b/omniauth-auth0.gemspec @@ -21,7 +21,7 @@ omniauth-auth0 is the OmniAuth strategy for Auth0. s.executables = `git ls-files -- bin/*`.split('\n').map{ |f| File.basename(f) } s.require_paths = ['lib'] - s.add_runtime_dependency 'jwt', '~> 2' + s.add_runtime_dependency 'jwt', '>= 2', '< 4' s.add_runtime_dependency 'omniauth', '~> 2' s.add_runtime_dependency 'omniauth-oauth2', '~> 1' diff --git a/spec/omniauth/auth0/jwt_validator_spec.rb b/spec/omniauth/auth0/jwt_validator_spec.rb index 38539a4..2c0d70b 100644 --- a/spec/omniauth/auth0/jwt_validator_spec.rb +++ b/spec/omniauth/auth0/jwt_validator_spec.rb @@ -618,7 +618,12 @@ iat: past_timecode, aud: client_id } - token = make_rs256_token(payload) + 'bad' + # Swap in a signature from a different payload so the segment stays + # valid base64 (JWT 3.x raises Base64DecodeError before verifying + # otherwise) but no longer matches the token. + header_segment, payload_segment, _signature = make_rs256_token(payload).split('.') + other_signature = make_rs256_token(payload.merge(sub: 'other')).split('.').last + token = [header_segment, payload_segment, other_signature].join('.') expect do verified_token = make_jwt_validator(opt_domain: domain).verify(token) end.to raise_error(an_instance_of(JWT::VerificationError).and having_attributes({