Replace python-jose with PyJWT to eliminate ecdsa vulnerability

This commit is contained in:
maziggy
2026-01-26 13:24:15 +01:00
parent 4b2d8b51e0
commit 6b0e3e7964
3 changed files with 8 additions and 2 deletions
+5
View File
@@ -0,0 +1,5 @@
Collecting PyJWT
Downloading PyJWT-2.10.1-py3-none-any.whl.metadata (4.0 kB)
Downloading PyJWT-2.10.1-py3-none-any.whl (22 kB)
Installing collected packages: PyJWT
Successfully installed PyJWT-2.10.1
+2 -1
View File
@@ -4,9 +4,10 @@ import secrets
from datetime import datetime, timedelta
from typing import Annotated
import jwt
from fastapi import Depends, Header, HTTPException, status
from fastapi.security import HTTPAuthorizationCredentials, HTTPBearer
from jose import JWTError, jwt
from jwt.exceptions import PyJWTError as JWTError
from passlib.context import CryptContext
from sqlalchemy import select
from sqlalchemy.ext.asyncio import AsyncSession
+1 -1
View File
@@ -38,7 +38,7 @@ qrcode[pil]>=7.4.0
psutil>=6.0.0
# Authentication
python-jose[cryptography]>=3.3.0
PyJWT>=2.8.0
passlib[bcrypt]>=1.7.4
# Development