Upgrade PyJWT to 2.10.0+ #655
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Summary
<2.10.0to>=2.10.0requires-pythonfrom>=3.8to>=3.9(PyJWT 2.10.0 dropped Python 3.8 support)subDetails
PyJWT 2.10.0 added validation that the
sub(subject) claim must be a string per RFC 7519. The existing code was storing a dict ({'access_token': ..., 'token_type': 'Bearer'}) in thesubclaim, which now fails withInvalidSubjectError: Subject must be a string.The fix changes from using the reserved
subclaim to a customaccess_token_dataclaim, which is not subject to the same validation requirements.Test plan