Skip to content

Commit 33f973b

Browse files
authored
[8.16] Bump json-smart and oauth2-oidc-sdk (#122737) (#122915)
* Bump json-smart and oauth2-oidc-sdk (#122737) * Bump json-smart and oauth2-oidc-sdk --------- Co-authored-by: elasticsearchmachine <[email protected]> (cherry picked from commit e166645) # Conflicts: # gradle/verification-metadata.xml * fixup! Add back verification data for test dep
1 parent bfd77c9 commit 33f973b

File tree

7 files changed

+43
-54
lines changed

7 files changed

+43
-54
lines changed

docs/changelog/122737.yaml

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
pr: 122737
2+
summary: Bump json-smart and oauth2-oidc-sdk
3+
area: Authentication
4+
type: upgrade
5+
issues: []

gradle/verification-metadata.xml

Lines changed: 14 additions & 36 deletions
Original file line numberDiff line numberDiff line change
@@ -974,36 +974,24 @@
974974
<sha256 value="e8c1c594e2425bdbea2d860de55c69b69fc5d59454452449a0f0913c2a5b8a31" origin="Generated by Gradle"/>
975975
</artifact>
976976
</component>
977+
<component group="com.nimbusds" name="nimbus-jose-jwt" version="10.0.1">
978+
<artifact name="nimbus-jose-jwt-10.0.1.jar">
979+
<sha256 value="f28dbd9ab128324f05050d76b78469d3a9cd83e0319aabc68d1c276e3923e13a" origin="Generated by Gradle"/>
980+
</artifact>
981+
</component>
977982
<component group="com.nimbusds" name="nimbus-jose-jwt" version="4.41.1">
978983
<artifact name="nimbus-jose-jwt-4.41.1.jar">
979984
<sha256 value="fbfd0d5f2b2f86758b821daa5e79b5d7c965edd9dc1b2cc80b515df1c6ddc22d" origin="Generated by Gradle"/>
980985
</artifact>
981986
</component>
982-
<component group="com.nimbusds" name="nimbus-jose-jwt" version="9.37.3">
983-
<artifact name="nimbus-jose-jwt-9.37.3.jar">
984-
<sha256 value="12ae4a3a260095d7aeba2adea7ae396e8b9570db8b7b409e09a824c219cc0444" origin="Generated by Gradle">
985-
<also-trust value="afc63b689d881439b95f343b1dca750391edac63b87392be4d90d19c94ccafbe"/>
986-
</sha256>
987-
</artifact>
988-
</component>
989987
<component group="com.nimbusds" name="nimbus-jose-jwt" version="9.8.1">
990988
<artifact name="nimbus-jose-jwt-9.8.1.jar">
991989
<sha256 value="7664cf8c6f2adadf600287812b32878277beda54912eab9d4c2932cd50cb704a" origin="Generated by Gradle"/>
992990
</artifact>
993991
</component>
994-
<component group="com.nimbusds" name="oauth2-oidc-sdk" version="11.10.1">
995-
<artifact name="oauth2-oidc-sdk-11.10.1.jar">
996-
<sha256 value="9e51b2c17503cdd3eb97f41491c712aff7783bb3c67185d789f44ccf2a603b26" origin="Generated by Gradle"/>
997-
</artifact>
998-
</component>
999-
<component group="com.nimbusds" name="oauth2-oidc-sdk" version="11.9.1">
1000-
<artifact name="oauth2-oidc-sdk-11.9.1.jar">
1001-
<sha256 value="0820c9690966304d075347b88e81ae490213440fc4d2c84f3d370d41941b2b9c" origin="Generated by Gradle"/>
1002-
</artifact>
1003-
</component>
1004-
<component group="com.nimbusds" name="oauth2-oidc-sdk" version="9.37">
1005-
<artifact name="oauth2-oidc-sdk-9.37.jar">
1006-
<sha256 value="44a04bbed5ae3f6d198aa73ee6b545c476e528ec1a267ef3e9f7033f886dd6fe" origin="Generated by Gradle"/>
992+
<component group="com.nimbusds" name="oauth2-oidc-sdk" version="11.22.2">
993+
<artifact name="oauth2-oidc-sdk-11.22.2.jar">
994+
<sha256 value="64fab42f17bf8e0efb193dd34da716ef7abb7515234036119df1776b808dc066" origin="Generated by Gradle"/>
1007995
</artifact>
1008996
</component>
1009997
<component group="com.perforce" name="p4java" version="2015.2.1365273">
@@ -1759,34 +1747,24 @@
17591747
<sha256 value="0972bbc99437c4163acd09b630e6c77eab4cfab8a9594621c95466c0c6645396" origin="Generated by Gradle"/>
17601748
</artifact>
17611749
</component>
1762-
<component group="net.minidev" name="accessors-smart" version="2.5.0">
1763-
<artifact name="accessors-smart-2.5.0.jar">
1764-
<sha256 value="12314fc6881d66a413fd66370787adba16e504fbf7e138690b0f3952e3fbd321" origin="Generated by Gradle"/>
1750+
<component group="net.minidev" name="accessors-smart" version="2.5.2">
1751+
<artifact name="accessors-smart-2.5.2.jar">
1752+
<sha256 value="9b8a7bc43861d6156c021166d941fb7dddbe4463e2fa5ee88077e4b01452a836" origin="Generated by Gradle"/>
17651753
</artifact>
17661754
</component>
17671755
<component group="net.minidev" name="json-smart" version="2.3">
17681756
<artifact name="json-smart-2.3.jar">
17691757
<sha256 value="903f48c8aa4c3f6426440b8d32de89fa1dc23b1169abde25e4e1d068aa67708b" origin="Generated by Gradle"/>
17701758
</artifact>
17711759
</component>
1772-
<component group="net.minidev" name="json-smart" version="2.4.10">
1773-
<artifact name="json-smart-2.4.10.jar">
1774-
<sha256 value="70cab5e9488630dc631b1fc6e7fa550d95cddd19ba14db39ceca7cabfbd4e5ae" origin="Generated by Gradle"/>
1775-
</artifact>
1776-
</component>
17771760
<component group="net.minidev" name="json-smart" version="2.4.2">
17781761
<artifact name="json-smart-2.4.2.jar">
17791762
<sha256 value="64072f56d9dff5040b2acec477c5d5e6bcebfc88c508f12acb26072d07942146" origin="Generated by Gradle"/>
17801763
</artifact>
17811764
</component>
1782-
<component group="net.minidev" name="json-smart" version="2.5.0">
1783-
<artifact name="json-smart-2.5.0.jar">
1784-
<sha256 value="432b9e545848c4141b80717b26e367f83bf33f19250a228ce75da6e967da2bc7" origin="Generated by Gradle"/>
1785-
</artifact>
1786-
</component>
1787-
<component group="net.minidev" name="json-smart" version="2.5.1">
1788-
<artifact name="json-smart-2.5.1.jar">
1789-
<sha256 value="86c0c189581b79b57b0719f443a724e9f628ffbb9eef645cf79194f5973a1001" origin="Generated by Gradle"/>
1765+
<component group="net.minidev" name="json-smart" version="2.5.2">
1766+
<artifact name="json-smart-2.5.2.jar">
1767+
<sha256 value="4fbdedb0105cedc7f766b95c297d2e88fb6a560da48f3bbaa0cc538ea8b7bf71" origin="Generated by Gradle"/>
17901768
</artifact>
17911769
</component>
17921770
<component group="net.nextencia" name="rrdiagram" version="0.9.4">

modules/repository-azure/build.gradle

Lines changed: 5 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -62,20 +62,20 @@ dependencies {
6262
api "com.github.stephenc.jcip:jcip-annotations:1.0-1"
6363
api "com.nimbusds:content-type:2.3"
6464
api "com.nimbusds:lang-tag:1.7"
65-
api("com.nimbusds:nimbus-jose-jwt:9.37.3"){
65+
api("com.nimbusds:nimbus-jose-jwt:10.0.1"){
6666
exclude group: 'com.google.crypto.tink', module: 'tink' // it's an optional dependency on which we don't rely
6767
}
68-
api("com.nimbusds:oauth2-oidc-sdk:11.9.1"){
68+
api("com.nimbusds:oauth2-oidc-sdk:11.22.2"){
6969
exclude group: 'com.google.crypto.tink', module: 'tink' // it's an optional dependency on which we don't rely
7070
}
7171
api "jakarta.activation:jakarta.activation-api:1.2.1"
7272
api "jakarta.xml.bind:jakarta.xml.bind-api:2.3.3"
7373
api "net.java.dev.jna:jna-platform:${versions.jna}" // Maven says 5.14.0 but this aligns with the Elasticsearch-wide version
7474
api "net.java.dev.jna:jna:${versions.jna}" // Maven says 5.14.0 but this aligns with the Elasticsearch-wide version
75-
api "net.minidev:accessors-smart:2.5.0"
76-
api "net.minidev:json-smart:2.5.0"
75+
api "net.minidev:accessors-smart:2.5.2"
76+
api "net.minidev:json-smart:2.5.2"
7777
api "org.codehaus.woodstox:stax2-api:4.2.2"
78-
api "org.ow2.asm:asm:9.3"
78+
api "org.ow2.asm:asm:9.7.1"
7979

8080
runtimeOnly "com.google.code.gson:gson:2.11.0"
8181
runtimeOnly "org.cryptomator:siv-mode:1.5.2"
@@ -189,11 +189,6 @@ tasks.named("thirdPartyAudit").configure {
189189
'org.bouncycastle.cert.X509CertificateHolder',
190190
'org.bouncycastle.cert.jcajce.JcaX509CertificateHolder',
191191
'org.bouncycastle.cert.jcajce.JcaX509v3CertificateBuilder',
192-
'org.bouncycastle.crypto.InvalidCipherTextException',
193-
'org.bouncycastle.crypto.engines.AESEngine',
194-
'org.bouncycastle.crypto.modes.GCMBlockCipher',
195-
'org.bouncycastle.jcajce.provider.BouncyCastleFipsProvider',
196-
'org.bouncycastle.jce.provider.BouncyCastleProvider',
197192
'org.bouncycastle.openssl.PEMKeyPair',
198193
'org.bouncycastle.openssl.PEMParser',
199194
'org.bouncycastle.openssl.jcajce.JcaPEMKeyConverter',

x-pack/plugin/security/build.gradle

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -79,21 +79,21 @@ dependencies {
7979
runtimeOnly "joda-time:joda-time:2.10.10"
8080

8181
// Dependencies for oidc
82-
api "com.nimbusds:oauth2-oidc-sdk:11.10.1"
82+
api "com.nimbusds:oauth2-oidc-sdk:11.22.2"
8383
api project(path: xpackModule('security:lib:nimbus-jose-jwt-modified'), configuration: 'shadow')
8484
if (isEclipse) {
8585
/*
8686
* Eclipse can't pick up the shadow dependency so we point it at the unmodified version of the library
8787
* so it can compile things.
8888
*/
89-
api "com.nimbusds:nimbus-jose-jwt:9.37.3"
89+
api "com.nimbusds:nimbus-jose-jwt:10.0.1"
9090
}
91-
api "com.nimbusds:lang-tag:1.4.4"
91+
api "com.nimbusds:lang-tag:1.7"
9292
api "com.sun.mail:jakarta.mail:1.6.3"
9393
api "net.jcip:jcip-annotations:1.0"
94-
api "net.minidev:json-smart:2.5.1"
95-
api "net.minidev:accessors-smart:2.4.2"
96-
api "org.ow2.asm:asm:8.0.1"
94+
api "net.minidev:json-smart:2.5.2"
95+
api "net.minidev:accessors-smart:2.5.2"
96+
api "org.ow2.asm:asm:9.7.1"
9797

9898
testImplementation "org.elasticsearch:mocksocket:${versions.mocksocket}"
9999

x-pack/plugin/security/lib/nimbus-jose-jwt-modified-part1/build.gradle

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ apply plugin: 'com.gradleup.shadow'
1111
// See the build.gradle file in the parent directory for an explanation of this unusual build
1212

1313
dependencies {
14-
implementation "com.nimbusds:nimbus-jose-jwt:9.37.3"
14+
implementation "com.nimbusds:nimbus-jose-jwt:10.0.1"
1515
}
1616

1717
tasks.named('shadowJar').configure {

x-pack/plugin/security/lib/nimbus-jose-jwt-modified/build.gradle

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ apply plugin: 'com.gradleup.shadow'
1111
// See the build.gradle file in the parent directory for an explanation of this unusual build
1212

1313
dependencies {
14-
implementation "com.nimbusds:nimbus-jose-jwt:9.37.3"
14+
implementation "com.nimbusds:nimbus-jose-jwt:10.0.1"
1515
implementation project(path: xpackModule('security:lib:nimbus-jose-jwt-modified-part2'), configuration: 'shadow')
1616
}
1717

x-pack/plugin/security/lib/nimbus-jose-jwt-modified/src/main/java/com/nimbusds/jose/util/JSONObjectUtils.java

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -13,6 +13,7 @@
1313
import java.security.PrivilegedActionException;
1414
import java.security.PrivilegedExceptionAction;
1515
import java.text.ParseException;
16+
import java.util.Date;
1617
import java.util.List;
1718
import java.util.Map;
1819

@@ -192,6 +193,16 @@ public static Base64URL getBase64URL(final Map<String, Object> o, final String k
192193
}
193194
}
194195

196+
public static Date getEpochSecondAsDate(final Map<String, Object> o, final String key) throws ParseException {
197+
try {
198+
return AccessController.doPrivileged(
199+
(PrivilegedExceptionAction<Date>) () -> org.elasticsearch.nimbus.jose.util.JSONObjectUtils.getEpochSecondAsDate(o, key)
200+
);
201+
} catch (PrivilegedActionException e) {
202+
throw (ParseException) e.getException();
203+
}
204+
}
205+
195206
public static String toJSONString(final Map<String, ?> o) {
196207
return AccessController.doPrivileged(
197208
(PrivilegedAction<String>) () -> org.elasticsearch.nimbus.jose.util.JSONObjectUtils.toJSONString(o)

0 commit comments

Comments
 (0)