[
https://issues.apache.org/jira/browse/SPARK-59552?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
L. C. Hsieh resolved SPARK-59552.
---------------------------------
Fix Version/s: connect-gateway-0.1.0
Resolution: Fixed
Issue resolved by pull request 29
[https://github.com/apache/spark-connect-gateway/pull/29]
> Upgrade jsonwebtoken to 10 and select the rust_crypto provider
> --------------------------------------------------------------
>
> Key: SPARK-59552
> URL: https://issues.apache.org/jira/browse/SPARK-59552
> Project: Spark
> Issue Type: Sub-task
> Components: Connect
> Affects Versions: connect-gateway-0.1.0
> Reporter: L. C. Hsieh
> Assignee: L. C. Hsieh
> Priority: Major
> Labels: pull-request-available
> Fix For: connect-gateway-0.1.0
>
>
> Move `jsonwebtoken` from 9 to 10, choosing the `rust_crypto` backend:
> jsonwebtoken = { version = "10", default-features = false,
> features = ["use_pem", "rust_crypto"] }
> Version 10 makes the crypto backend pluggable and refuses to guess one. What
> makes this more than a version bump is that it fails at RUNTIME, not at
> compile
> time: `jsonwebtoken = "10"` on its own builds cleanly, so the gateway would
> start
> normally and panic on the first JWT it verified.
> Could not automatically determine the process-level CryptoProvider from
> jsonwebtoken crate features. Call CryptoProvider::install_default() before
> this point to select a provider manually, or make sure exactly one of the
> 'rust_crypto' and 'aws_lc_rs' features is enabled.
> `rust_crypto` is the pure-Rust provider, consistent with this repo's existing
> choices elsewhere (`reqwest` with `rustls-tls`, `opentelemetry-otlp` with
> `tls-ring`), and it adds no C toolchain dependency: the crates it pulls in are
> `rsa`, `p256`, `p384`, `sha2`, `hmac` and `ed25519-dalek`, all pure Rust.
> `ring`
> already appears in the tree via `rustls` and is unchanged by this patch. That
> matters for the distroless runtime image.
> `use_pem` has to be listed explicitly. It is a *default* feature, so
> `default-features = false` with only a provider fails to compile --
> `EncodingKey::from_rsa_pem`, which the JWT and OIDC verifiers both use, lives
> behind it.
> Every algorithm the gateway's config accepts was checked to sign and verify
> under this provider, not just to compile: HS256/384/512, RS256/384/512,
> PS256/384/512, ES256 and ES384 all round-trip. A provider missing one of these
> would have failed only for the users who configured that algorithm.
> The large `Cargo.lock` diff is expected -- selecting a provider replaces the
> crypto implementation stack rather than bumping one crate.
> Verified: 204 tests pass (the same as the baseline on main), including the 17
> `jwt::` and `oidc::` tests -- the 14 that dependabot's #6 reported as failing
> are
> among them. `cargo clippy --workspace --all-targets -D warnings` and
> `cargo fmt --check` are clean.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]