From 6b0e3e79644b9ca6279e640f549883fed047c0f3 Mon Sep 17 00:00:00 2001 From: maziggy Date: Mon, 26 Jan 2026 13:24:15 +0100 Subject: [PATCH] Replace python-jose with PyJWT to eliminate ecdsa vulnerability --- =2.8.0 | 5 +++++ backend/app/core/auth.py | 3 ++- requirements.txt | 2 +- 3 files changed, 8 insertions(+), 2 deletions(-) create mode 100644 =2.8.0 diff --git a/=2.8.0 b/=2.8.0 new file mode 100644 index 000000000..9f7171c00 --- /dev/null +++ b/=2.8.0 @@ -0,0 +1,5 @@ +Collecting PyJWT + Downloading PyJWT-2.10.1-py3-none-any.whl.metadata (4.0 kB) +Downloading PyJWT-2.10.1-py3-none-any.whl (22 kB) +Installing collected packages: PyJWT +Successfully installed PyJWT-2.10.1 diff --git a/backend/app/core/auth.py b/backend/app/core/auth.py index f79a66b49..fb3c1c367 100644 --- a/backend/app/core/auth.py +++ b/backend/app/core/auth.py @@ -4,9 +4,10 @@ import secrets from datetime import datetime, timedelta from typing import Annotated +import jwt from fastapi import Depends, Header, HTTPException, status from fastapi.security import HTTPAuthorizationCredentials, HTTPBearer -from jose import JWTError, jwt +from jwt.exceptions import PyJWTError as JWTError from passlib.context import CryptContext from sqlalchemy import select from sqlalchemy.ext.asyncio import AsyncSession diff --git a/requirements.txt b/requirements.txt index 27238e913..1a7fc23e3 100644 --- a/requirements.txt +++ b/requirements.txt @@ -38,7 +38,7 @@ qrcode[pil]>=7.4.0 psutil>=6.0.0 # Authentication -python-jose[cryptography]>=3.3.0 +PyJWT>=2.8.0 passlib[bcrypt]>=1.7.4 # Development