Skip to content

Commit 4765745

Browse files
jfredenelasticsearchmachine
andauthored
Bump json-smart and oauth2-oidc-sdk (elastic#122737) (elastic#122836)
* Bump json-smart and oauth2-oidc-sdk --------- Co-authored-by: elasticsearchmachine <[email protected]>
1 parent 63d0b6a commit 4765745

File tree

7 files changed

+43
-84
lines changed

7 files changed

+43
-84
lines changed

docs/changelog/122737.yaml

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
pr: 122737
2+
summary: Bump json-smart and oauth2-oidc-sdk
3+
area: Authentication
4+
type: upgrade
5+
issues: []

gradle/verification-metadata.xml

Lines changed: 14 additions & 66 deletions
Original file line numberDiff line numberDiff line change
@@ -984,36 +984,19 @@
984984
<sha256 value="e8c1c594e2425bdbea2d860de55c69b69fc5d59454452449a0f0913c2a5b8a31" origin="Generated by Gradle"/>
985985
</artifact>
986986
</component>
987+
<component group="com.nimbusds" name="nimbus-jose-jwt" version="10.0.1">
988+
<artifact name="nimbus-jose-jwt-10.0.1.jar">
989+
<sha256 value="f28dbd9ab128324f05050d76b78469d3a9cd83e0319aabc68d1c276e3923e13a" origin="Generated by Gradle"/>
990+
</artifact>
991+
</component>
987992
<component group="com.nimbusds" name="nimbus-jose-jwt" version="4.41.1">
988993
<artifact name="nimbus-jose-jwt-4.41.1.jar">
989994
<sha256 value="fbfd0d5f2b2f86758b821daa5e79b5d7c965edd9dc1b2cc80b515df1c6ddc22d" origin="Generated by Gradle"/>
990995
</artifact>
991996
</component>
992-
<component group="com.nimbusds" name="nimbus-jose-jwt" version="9.37.3">
993-
<artifact name="nimbus-jose-jwt-9.37.3.jar">
994-
<sha256 value="12ae4a3a260095d7aeba2adea7ae396e8b9570db8b7b409e09a824c219cc0444" origin="Generated by Gradle">
995-
<also-trust value="afc63b689d881439b95f343b1dca750391edac63b87392be4d90d19c94ccafbe"/>
996-
</sha256>
997-
</artifact>
998-
</component>
999-
<component group="com.nimbusds" name="nimbus-jose-jwt" version="9.8.1">
1000-
<artifact name="nimbus-jose-jwt-9.8.1.jar">
1001-
<sha256 value="7664cf8c6f2adadf600287812b32878277beda54912eab9d4c2932cd50cb704a" origin="Generated by Gradle"/>
1002-
</artifact>
1003-
</component>
1004-
<component group="com.nimbusds" name="oauth2-oidc-sdk" version="11.10.1">
1005-
<artifact name="oauth2-oidc-sdk-11.10.1.jar">
1006-
<sha256 value="9e51b2c17503cdd3eb97f41491c712aff7783bb3c67185d789f44ccf2a603b26" origin="Generated by Gradle"/>
1007-
</artifact>
1008-
</component>
1009-
<component group="com.nimbusds" name="oauth2-oidc-sdk" version="11.9.1">
1010-
<artifact name="oauth2-oidc-sdk-11.9.1.jar">
1011-
<sha256 value="0820c9690966304d075347b88e81ae490213440fc4d2c84f3d370d41941b2b9c" origin="Generated by Gradle"/>
1012-
</artifact>
1013-
</component>
1014-
<component group="com.nimbusds" name="oauth2-oidc-sdk" version="9.37">
1015-
<artifact name="oauth2-oidc-sdk-9.37.jar">
1016-
<sha256 value="44a04bbed5ae3f6d198aa73ee6b545c476e528ec1a267ef3e9f7033f886dd6fe" origin="Generated by Gradle"/>
997+
<component group="com.nimbusds" name="oauth2-oidc-sdk" version="11.22.2">
998+
<artifact name="oauth2-oidc-sdk-11.22.2.jar">
999+
<sha256 value="64fab42f17bf8e0efb193dd34da716ef7abb7515234036119df1776b808dc066" origin="Generated by Gradle"/>
10171000
</artifact>
10181001
</component>
10191002
<component group="com.perforce" name="p4java" version="2015.2.1365273">
@@ -1779,34 +1762,24 @@
17791762
<sha256 value="0972bbc99437c4163acd09b630e6c77eab4cfab8a9594621c95466c0c6645396" origin="Generated by Gradle"/>
17801763
</artifact>
17811764
</component>
1782-
<component group="net.minidev" name="accessors-smart" version="2.5.0">
1783-
<artifact name="accessors-smart-2.5.0.jar">
1784-
<sha256 value="12314fc6881d66a413fd66370787adba16e504fbf7e138690b0f3952e3fbd321" origin="Generated by Gradle"/>
1765+
<component group="net.minidev" name="accessors-smart" version="2.5.2">
1766+
<artifact name="accessors-smart-2.5.2.jar">
1767+
<sha256 value="9b8a7bc43861d6156c021166d941fb7dddbe4463e2fa5ee88077e4b01452a836" origin="Generated by Gradle"/>
17851768
</artifact>
17861769
</component>
17871770
<component group="net.minidev" name="json-smart" version="2.3">
17881771
<artifact name="json-smart-2.3.jar">
17891772
<sha256 value="903f48c8aa4c3f6426440b8d32de89fa1dc23b1169abde25e4e1d068aa67708b" origin="Generated by Gradle"/>
17901773
</artifact>
17911774
</component>
1792-
<component group="net.minidev" name="json-smart" version="2.4.10">
1793-
<artifact name="json-smart-2.4.10.jar">
1794-
<sha256 value="70cab5e9488630dc631b1fc6e7fa550d95cddd19ba14db39ceca7cabfbd4e5ae" origin="Generated by Gradle"/>
1795-
</artifact>
1796-
</component>
17971775
<component group="net.minidev" name="json-smart" version="2.4.2">
17981776
<artifact name="json-smart-2.4.2.jar">
17991777
<sha256 value="64072f56d9dff5040b2acec477c5d5e6bcebfc88c508f12acb26072d07942146" origin="Generated by Gradle"/>
18001778
</artifact>
18011779
</component>
1802-
<component group="net.minidev" name="json-smart" version="2.5.0">
1803-
<artifact name="json-smart-2.5.0.jar">
1804-
<sha256 value="432b9e545848c4141b80717b26e367f83bf33f19250a228ce75da6e967da2bc7" origin="Generated by Gradle"/>
1805-
</artifact>
1806-
</component>
1807-
<component group="net.minidev" name="json-smart" version="2.5.1">
1808-
<artifact name="json-smart-2.5.1.jar">
1809-
<sha256 value="86c0c189581b79b57b0719f443a724e9f628ffbb9eef645cf79194f5973a1001" origin="Generated by Gradle"/>
1780+
<component group="net.minidev" name="json-smart" version="2.5.2">
1781+
<artifact name="json-smart-2.5.2.jar">
1782+
<sha256 value="4fbdedb0105cedc7f766b95c297d2e88fb6a560da48f3bbaa0cc538ea8b7bf71" origin="Generated by Gradle"/>
18101783
</artifact>
18111784
</component>
18121785
<component group="net.nextencia" name="rrdiagram" version="0.9.4">
@@ -4408,31 +4381,6 @@
44084381
<sha256 value="ca5b8d11569e53921b0e3486469e7c674361c79845dad3d514f38ab6e0c8c10a" origin="Generated by Gradle"/>
44094382
</artifact>
44104383
</component>
4411-
<component group="org.ow2.asm" name="asm" version="9.2">
4412-
<artifact name="asm-9.2.jar">
4413-
<sha256 value="b9d4fe4d71938df38839f0eca42aaaa64cf8b313d678da036f0cb3ca199b47f5" origin="Generated by Gradle"/>
4414-
</artifact>
4415-
</component>
4416-
<component group="org.ow2.asm" name="asm" version="9.3">
4417-
<artifact name="asm-9.3.jar">
4418-
<sha256 value="1263369b59e29c943918de11d6d6152e2ec6085ce63e5710516f8c67d368e4bc" origin="Generated by Gradle"/>
4419-
</artifact>
4420-
</component>
4421-
<component group="org.ow2.asm" name="asm" version="9.4">
4422-
<artifact name="asm-9.4.jar">
4423-
<sha256 value="39d0e2b3dc45af65a09b097945750a94a126e052e124f93468443a1d0e15f381" origin="Generated by Gradle"/>
4424-
</artifact>
4425-
</component>
4426-
<component group="org.ow2.asm" name="asm" version="9.5">
4427-
<artifact name="asm-9.5.jar">
4428-
<sha256 value="b62e84b5980729751b0458c534cf1366f727542bb8d158621335682a460f0353" origin="Generated by Gradle"/>
4429-
</artifact>
4430-
</component>
4431-
<component group="org.ow2.asm" name="asm" version="9.6">
4432-
<artifact name="asm-9.6.jar">
4433-
<sha256 value="3c6fac2424db3d4a853b669f4e3d1d9c3c552235e19a319673f887083c2303a1" origin="Generated by Gradle"/>
4434-
</artifact>
4435-
</component>
44364384
<component group="org.ow2.asm" name="asm" version="9.7.1">
44374385
<artifact name="asm-9.7.1.jar">
44384386
<sha256 value="8cadd43ac5eb6d09de05faecca38b917a040bb9139c7edeb4cc81c740b713281" origin="Generated by Gradle"/>

modules/repository-azure/build.gradle

Lines changed: 5 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -63,20 +63,20 @@ dependencies {
6363
api "com.github.stephenc.jcip:jcip-annotations:1.0-1"
6464
api "com.nimbusds:content-type:2.3"
6565
api "com.nimbusds:lang-tag:1.7"
66-
api("com.nimbusds:nimbus-jose-jwt:9.37.3"){
66+
api("com.nimbusds:nimbus-jose-jwt:10.0.1"){
6767
exclude group: 'com.google.crypto.tink', module: 'tink' // it's an optional dependency on which we don't rely
6868
}
69-
api("com.nimbusds:oauth2-oidc-sdk:11.9.1"){
69+
api("com.nimbusds:oauth2-oidc-sdk:11.22.2"){
7070
exclude group: 'com.google.crypto.tink', module: 'tink' // it's an optional dependency on which we don't rely
7171
}
7272
api "jakarta.activation:jakarta.activation-api:1.2.1"
7373
api "jakarta.xml.bind:jakarta.xml.bind-api:2.3.3"
7474
api "net.java.dev.jna:jna-platform:${versions.jna}" // Maven says 5.14.0 but this aligns with the Elasticsearch-wide version
7575
api "net.java.dev.jna:jna:${versions.jna}" // Maven says 5.14.0 but this aligns with the Elasticsearch-wide version
76-
api "net.minidev:accessors-smart:2.5.0"
77-
api "net.minidev:json-smart:2.5.0"
76+
api "net.minidev:accessors-smart:2.5.2"
77+
api "net.minidev:json-smart:2.5.2"
7878
api "org.codehaus.woodstox:stax2-api:4.2.2"
79-
api "org.ow2.asm:asm:9.3"
79+
api "org.ow2.asm:asm:9.7.1"
8080

8181
runtimeOnly "com.google.code.gson:gson:2.11.0"
8282
runtimeOnly "org.cryptomator:siv-mode:1.5.2"
@@ -190,11 +190,6 @@ tasks.named("thirdPartyAudit").configure {
190190
'org.bouncycastle.cert.X509CertificateHolder',
191191
'org.bouncycastle.cert.jcajce.JcaX509CertificateHolder',
192192
'org.bouncycastle.cert.jcajce.JcaX509v3CertificateBuilder',
193-
'org.bouncycastle.crypto.InvalidCipherTextException',
194-
'org.bouncycastle.crypto.engines.AESEngine',
195-
'org.bouncycastle.crypto.modes.GCMBlockCipher',
196-
'org.bouncycastle.jcajce.provider.BouncyCastleFipsProvider',
197-
'org.bouncycastle.jce.provider.BouncyCastleProvider',
198193
'org.bouncycastle.openssl.PEMKeyPair',
199194
'org.bouncycastle.openssl.PEMParser',
200195
'org.bouncycastle.openssl.jcajce.JcaPEMKeyConverter',

x-pack/plugin/security/build.gradle

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -79,21 +79,21 @@ dependencies {
7979
runtimeOnly "joda-time:joda-time:2.10.10"
8080

8181
// Dependencies for oidc
82-
api "com.nimbusds:oauth2-oidc-sdk:11.10.1"
82+
api "com.nimbusds:oauth2-oidc-sdk:11.22.2"
8383
api project(path: xpackModule('security:lib:nimbus-jose-jwt-modified'), configuration: 'shadow')
8484
if (isEclipse) {
8585
/*
8686
* Eclipse can't pick up the shadow dependency so we point it at the unmodified version of the library
8787
* so it can compile things.
8888
*/
89-
api "com.nimbusds:nimbus-jose-jwt:9.37.3"
89+
api "com.nimbusds:nimbus-jose-jwt:10.0.1"
9090
}
91-
api "com.nimbusds:lang-tag:1.4.4"
91+
api "com.nimbusds:lang-tag:1.7"
9292
api "com.sun.mail:jakarta.mail:1.6.3"
9393
api "net.jcip:jcip-annotations:1.0"
94-
api "net.minidev:json-smart:2.5.1"
95-
api "net.minidev:accessors-smart:2.4.2"
96-
api "org.ow2.asm:asm:8.0.1"
94+
api "net.minidev:json-smart:2.5.2"
95+
api "net.minidev:accessors-smart:2.5.2"
96+
api "org.ow2.asm:asm:9.7.1"
9797

9898
testImplementation "org.elasticsearch:mocksocket:${versions.mocksocket}"
9999

x-pack/plugin/security/lib/nimbus-jose-jwt-modified-part1/build.gradle

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ apply plugin: 'com.gradleup.shadow'
1111
// See the build.gradle file in the parent directory for an explanation of this unusual build
1212

1313
dependencies {
14-
implementation "com.nimbusds:nimbus-jose-jwt:9.37.3"
14+
implementation "com.nimbusds:nimbus-jose-jwt:10.0.1"
1515
}
1616

1717
tasks.named('shadowJar').configure {

x-pack/plugin/security/lib/nimbus-jose-jwt-modified/build.gradle

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ apply plugin: 'com.gradleup.shadow'
1111
// See the build.gradle file in the parent directory for an explanation of this unusual build
1212

1313
dependencies {
14-
implementation "com.nimbusds:nimbus-jose-jwt:9.37.3"
14+
implementation "com.nimbusds:nimbus-jose-jwt:10.0.1"
1515
implementation project(path: xpackModule('security:lib:nimbus-jose-jwt-modified-part2'), configuration: 'shadow')
1616
}
1717

x-pack/plugin/security/lib/nimbus-jose-jwt-modified/src/main/java/com/nimbusds/jose/util/JSONObjectUtils.java

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -13,6 +13,7 @@
1313
import java.security.PrivilegedActionException;
1414
import java.security.PrivilegedExceptionAction;
1515
import java.text.ParseException;
16+
import java.util.Date;
1617
import java.util.List;
1718
import java.util.Map;
1819

@@ -192,6 +193,16 @@ public static Base64URL getBase64URL(final Map<String, Object> o, final String k
192193
}
193194
}
194195

196+
public static Date getEpochSecondAsDate(final Map<String, Object> o, final String key) throws ParseException {
197+
try {
198+
return AccessController.doPrivileged(
199+
(PrivilegedExceptionAction<Date>) () -> org.elasticsearch.nimbus.jose.util.JSONObjectUtils.getEpochSecondAsDate(o, key)
200+
);
201+
} catch (PrivilegedActionException e) {
202+
throw (ParseException) e.getException();
203+
}
204+
}
205+
195206
public static String toJSONString(final Map<String, ?> o) {
196207
return AccessController.doPrivileged(
197208
(PrivilegedAction<String>) () -> org.elasticsearch.nimbus.jose.util.JSONObjectUtils.toJSONString(o)

0 commit comments

Comments
 (0)