refactor(auth): JWT ライブラリを python-jose から PyJWT へ移行し ecdsa 脆弱性を解消 - #481

Merged
yusuke0610 merged 1 commit into
mainfrom
refactor/replace-python-jose-with-pyjwt
Jul 8, 2026
Merged

refactor(auth): JWT ライブラリを python-jose から PyJWT へ移行し ecdsa 脆弱性を解消#481
yusuke0610 merged 1 commit into
mainfrom
refactor/replace-python-jose-with-pyjwt

Conversation

@yusuke0610

@yusuke0610yusuke0610 commented Jul 8, 2026

Copy link
Copy Markdown
Owner

背景

python-jose[cryptography] の推移的依存 ecdsa 0.19.2修正版の出ない脆弱性PYSEC-2026-1325(Minerva タイミング攻撃・P-256、CVSS 7.4)が存在し、CI の pip-audit全オープン PR・main 共通で fail していた。メンテナが「サイドチャネルは対象外」として修正しない方針のため requirements.txt の「バージョン引き上げ」運用が使えない。

対応

DevForge の JWT は RS256 のみapp/core/security/auth.py)で python-jose は cryptography バックエンドを使い、ecdsa 経路(ecdsa.SigningKey.sign_digest())は一切通らない。そのため脆弱性は実質非該当だが、依存ツリーから消すのが最もクリーンと判断し PyJWT[crypto] へ移行して ecdsa 依存自体を除去する。

  • auth.py: jose.JWTErrorjwt.PyJWTError(RS256 の署名・検証挙動は不変)
  • requirements.txt: python-jose[cryptography]==3.5.0PyJWT[crypto]==2.13.0
  • THIRD_PARTY_LICENSES.mdmake licenses で再生成
  • README.md / .claude/rules/backend/auth-security.md の JWT ライブラリ表記を更新

検証

  • pip-audit -r requirements.txtNo known vulnerabilities found(ecdsa がツリーから消失)
  • auth / security テスト 150 件 pass(HS256→RS256 拒否テスト含む)
  • make ci full green

影響範囲

このマージ後、blocker が解消されるため滞留中の Renovate PR(#466 / #467 / #468 / #470)も緑化してマージ可能になる。

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores

    • Updated the app’s authentication implementation to use a different JWT library, with no expected change to login or token behavior.
    • Refreshed related dependency and license listings to match the current setup.
  • Documentation

    • Aligned the README and internal guidance with the updated authentication stack.

python-jose の推移的依存 ecdsa 0.19.2 に修正版の出ない脆弱性
(PYSEC-2026-1325 / Minerva タイミング攻撃・P-256)があり、pip-audit が
全 PR・main 共通で fail していた。DevForge の JWT は RS256 のみで
cryptography バックエンドを使い ecdsa 経路は未使用のため、PyJWT[crypto]
へ移行して ecdsa 依存自体を除去する。
- auth.py: jose.JWTError → jwt.PyJWTError(RS256 の署名・検証挙動は不変)
- requirements.txt: python-jose[cryptography]==3.5.0 → PyJWT[crypto]==2.13.0
- THIRD_PARTY_LICENSES.md を make licenses で再生成
- README / auth-security.md の JWT ライブラリ表記を更新
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@github-actionsgithub-actionsBot added auth refactor リファクタリング documentation Improvements or additions to documentation backend バックエンド test テスト追加・修正 labels Jul 8, 2026
@coderabbitai

coderabbitaiBot commented Jul 8, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: a381b839-65b5-48d7-b1ce-a1bc15633d12

📥 Commits

Reviewing files that changed from the base of the PR and between 114f801 and a42100c.

📒 Files selected for processing (6)
  • .claude/rules/backend/auth-security.md
  • README.md
  • THIRD_PARTY_LICENSES.md
  • backend/app/core/security/auth.py
  • backend/requirements.txt
  • backend/tests/auth/test_token_manager.py

📝 Walkthrough

Walkthrough

The JWT library dependency is migrated from python-jose to PyJWT throughout the backend. The auth module's import and exception handling are updated to use jwt.PyJWTError, tests are adjusted, and requirements.txt, README, third-party license list, and internal rules documentation are updated accordingly.

Changes

JWT Library Migration

Layer / File(s)Summary
Core auth logic switched to PyJWT
backend/app/core/security/auth.py
Import changed from jose's jwt to direct import jwt; exception handling updated from JWTError to jwt.PyJWTError in key pair validation and token decoding, preserving the same 401 failure path.
Test suite updated for PyJWT import
backend/tests/auth/test_token_manager.py
JWT import switched from from jose import jwt to import jwt, so encode/decode calls now target PyJWT.
Dependency manifest and documentation updates
backend/requirements.txt, README.md, THIRD_PARTY_LICENSES.md, .claude/rules/backend/auth-security.md
python-jose[cryptography] replaced with PyJWT[crypto]==2.13.0 in requirements; README, license list, and rules doc updated to reflect PyJWT usage.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

  • yusuke0610/devforge#464: Both PRs modify backend/tests/auth/test_token_manager.py, updating JWT handling/imports and consolidating JWT claim assertions.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly matches the main change: migrating JWT auth from python-jose to PyJWT to address the ecdsa vulnerability.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch refactor/replace-python-jose-with-pyjwt

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@yusuke0610
yusuke0610 merged commit f0917a7 into mainJul 8, 2026
24 checks passed
@yusuke0610
yusuke0610 deleted the refactor/replace-python-jose-with-pyjwt branch July 20, 2026 12:25
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

authbackendバックエンドdocumentationImprovements or additions to documentationrefactorリファクタリングtestテスト追加・修正

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@yusuke0610
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

refactor(auth): JWT ライブラリを python-jose から PyJWT へ移行し ecdsa 脆弱性を解消 - #481

Merged
yusuke0610 merged 1 commit into
mainfrom
refactor/replace-python-jose-with-pyjwt
Jul 8, 2026
Merged

refactor(auth): JWT ライブラリを python-jose から PyJWT へ移行し ecdsa 脆弱性を解消#481
yusuke0610 merged 1 commit into
mainfrom
refactor/replace-python-jose-with-pyjwt

Conversation

@yusuke0610

@yusuke0610yusuke0610 commented Jul 8, 2026

Copy link
Copy Markdown
Owner

背景

python-jose[cryptography] の推移的依存 ecdsa 0.19.2修正版の出ない脆弱性PYSEC-2026-1325(Minerva タイミング攻撃・P-256、CVSS 7.4)が存在し、CI の pip-audit全オープン PR・main 共通で fail していた。メンテナが「サイドチャネルは対象外」として修正しない方針のため requirements.txt の「バージョン引き上げ」運用が使えない。

対応

DevForge の JWT は RS256 のみapp/core/security/auth.py)で python-jose は cryptography バックエンドを使い、ecdsa 経路(ecdsa.SigningKey.sign_digest())は一切通らない。そのため脆弱性は実質非該当だが、依存ツリーから消すのが最もクリーンと判断し PyJWT[crypto] へ移行して ecdsa 依存自体を除去する。

  • auth.py: jose.JWTErrorjwt.PyJWTError(RS256 の署名・検証挙動は不変)
  • requirements.txt: python-jose[cryptography]==3.5.0PyJWT[crypto]==2.13.0
  • THIRD_PARTY_LICENSES.mdmake licenses で再生成
  • README.md / .claude/rules/backend/auth-security.md の JWT ライブラリ表記を更新

検証

  • pip-audit -r requirements.txtNo known vulnerabilities found(ecdsa がツリーから消失)
  • auth / security テスト 150 件 pass(HS256→RS256 拒否テスト含む)
  • make ci full green

影響範囲

このマージ後、blocker が解消されるため滞留中の Renovate PR(#466 / #467 / #468 / #470)も緑化してマージ可能になる。

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores

    • Updated the app’s authentication implementation to use a different JWT library, with no expected change to login or token behavior.
    • Refreshed related dependency and license listings to match the current setup.
  • Documentation

    • Aligned the README and internal guidance with the updated authentication stack.

python-jose の推移的依存 ecdsa 0.19.2 に修正版の出ない脆弱性
(PYSEC-2026-1325 / Minerva タイミング攻撃・P-256)があり、pip-audit が
全 PR・main 共通で fail していた。DevForge の JWT は RS256 のみで
cryptography バックエンドを使い ecdsa 経路は未使用のため、PyJWT[crypto]
へ移行して ecdsa 依存自体を除去する。
- auth.py: jose.JWTError → jwt.PyJWTError(RS256 の署名・検証挙動は不変)
- requirements.txt: python-jose[cryptography]==3.5.0 → PyJWT[crypto]==2.13.0
- THIRD_PARTY_LICENSES.md を make licenses で再生成
- README / auth-security.md の JWT ライブラリ表記を更新
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@github-actionsgithub-actionsBot added auth refactor リファクタリング documentation Improvements or additions to documentation backend バックエンド test テスト追加・修正 labels Jul 8, 2026
@coderabbitai

coderabbitaiBot commented Jul 8, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: a381b839-65b5-48d7-b1ce-a1bc15633d12

📥 Commits

Reviewing files that changed from the base of the PR and between 114f801 and a42100c.

📒 Files selected for processing (6)
  • .claude/rules/backend/auth-security.md
  • README.md
  • THIRD_PARTY_LICENSES.md
  • backend/app/core/security/auth.py
  • backend/requirements.txt
  • backend/tests/auth/test_token_manager.py

📝 Walkthrough

Walkthrough

The JWT library dependency is migrated from python-jose to PyJWT throughout the backend. The auth module's import and exception handling are updated to use jwt.PyJWTError, tests are adjusted, and requirements.txt, README, third-party license list, and internal rules documentation are updated accordingly.

Changes

JWT Library Migration

Layer / File(s)Summary
Core auth logic switched to PyJWT
backend/app/core/security/auth.py
Import changed from jose's jwt to direct import jwt; exception handling updated from JWTError to jwt.PyJWTError in key pair validation and token decoding, preserving the same 401 failure path.
Test suite updated for PyJWT import
backend/tests/auth/test_token_manager.py
JWT import switched from from jose import jwt to import jwt, so encode/decode calls now target PyJWT.
Dependency manifest and documentation updates
backend/requirements.txt, README.md, THIRD_PARTY_LICENSES.md, .claude/rules/backend/auth-security.md
python-jose[cryptography] replaced with PyJWT[crypto]==2.13.0 in requirements; README, license list, and rules doc updated to reflect PyJWT usage.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

  • yusuke0610/devforge#464: Both PRs modify backend/tests/auth/test_token_manager.py, updating JWT handling/imports and consolidating JWT claim assertions.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly matches the main change: migrating JWT auth from python-jose to PyJWT to address the ecdsa vulnerability.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch refactor/replace-python-jose-with-pyjwt

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@yusuke0610
yusuke0610 merged commit f0917a7 into mainJul 8, 2026
24 checks passed
@yusuke0610
yusuke0610 deleted the refactor/replace-python-jose-with-pyjwt branch July 20, 2026 12:25
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

authbackendバックエンドdocumentationImprovements or additions to documentationrefactorリファクタリングtestテスト追加・修正

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@yusuke0610
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

refactor(auth): JWT ライブラリを python-jose から PyJWT へ移行し ecdsa 脆弱性を解消 - #481

Merged
yusuke0610 merged 1 commit into
mainfrom
refactor/replace-python-jose-with-pyjwt
Jul 8, 2026
Merged

refactor(auth): JWT ライブラリを python-jose から PyJWT へ移行し ecdsa 脆弱性を解消#481
yusuke0610 merged 1 commit into
mainfrom
refactor/replace-python-jose-with-pyjwt

Conversation

@yusuke0610

@yusuke0610yusuke0610 commented Jul 8, 2026

Copy link
Copy Markdown
Owner

背景

python-jose[cryptography] の推移的依存 ecdsa 0.19.2修正版の出ない脆弱性PYSEC-2026-1325(Minerva タイミング攻撃・P-256、CVSS 7.4)が存在し、CI の pip-audit全オープン PR・main 共通で fail していた。メンテナが「サイドチャネルは対象外」として修正しない方針のため requirements.txt の「バージョン引き上げ」運用が使えない。

対応

DevForge の JWT は RS256 のみapp/core/security/auth.py)で python-jose は cryptography バックエンドを使い、ecdsa 経路(ecdsa.SigningKey.sign_digest())は一切通らない。そのため脆弱性は実質非該当だが、依存ツリーから消すのが最もクリーンと判断し PyJWT[crypto] へ移行して ecdsa 依存自体を除去する。

  • auth.py: jose.JWTErrorjwt.PyJWTError(RS256 の署名・検証挙動は不変)
  • requirements.txt: python-jose[cryptography]==3.5.0PyJWT[crypto]==2.13.0
  • THIRD_PARTY_LICENSES.mdmake licenses で再生成
  • README.md / .claude/rules/backend/auth-security.md の JWT ライブラリ表記を更新

検証

  • pip-audit -r requirements.txtNo known vulnerabilities found(ecdsa がツリーから消失)
  • auth / security テスト 150 件 pass(HS256→RS256 拒否テスト含む)
  • make ci full green

影響範囲

このマージ後、blocker が解消されるため滞留中の Renovate PR(#466 / #467 / #468 / #470)も緑化してマージ可能になる。

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores

    • Updated the app’s authentication implementation to use a different JWT library, with no expected change to login or token behavior.
    • Refreshed related dependency and license listings to match the current setup.
  • Documentation

    • Aligned the README and internal guidance with the updated authentication stack.

python-jose の推移的依存 ecdsa 0.19.2 に修正版の出ない脆弱性
(PYSEC-2026-1325 / Minerva タイミング攻撃・P-256)があり、pip-audit が
全 PR・main 共通で fail していた。DevForge の JWT は RS256 のみで
cryptography バックエンドを使い ecdsa 経路は未使用のため、PyJWT[crypto]
へ移行して ecdsa 依存自体を除去する。
- auth.py: jose.JWTError → jwt.PyJWTError(RS256 の署名・検証挙動は不変)
- requirements.txt: python-jose[cryptography]==3.5.0 → PyJWT[crypto]==2.13.0
- THIRD_PARTY_LICENSES.md を make licenses で再生成
- README / auth-security.md の JWT ライブラリ表記を更新
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@github-actionsgithub-actionsBot added auth refactor リファクタリング documentation Improvements or additions to documentation backend バックエンド test テスト追加・修正 labels Jul 8, 2026
@coderabbitai

coderabbitaiBot commented Jul 8, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: a381b839-65b5-48d7-b1ce-a1bc15633d12

📥 Commits

Reviewing files that changed from the base of the PR and between 114f801 and a42100c.

📒 Files selected for processing (6)
  • .claude/rules/backend/auth-security.md
  • README.md
  • THIRD_PARTY_LICENSES.md
  • backend/app/core/security/auth.py
  • backend/requirements.txt
  • backend/tests/auth/test_token_manager.py

📝 Walkthrough

Walkthrough

The JWT library dependency is migrated from python-jose to PyJWT throughout the backend. The auth module's import and exception handling are updated to use jwt.PyJWTError, tests are adjusted, and requirements.txt, README, third-party license list, and internal rules documentation are updated accordingly.

Changes

JWT Library Migration

Layer / File(s)Summary
Core auth logic switched to PyJWT
backend/app/core/security/auth.py
Import changed from jose's jwt to direct import jwt; exception handling updated from JWTError to jwt.PyJWTError in key pair validation and token decoding, preserving the same 401 failure path.
Test suite updated for PyJWT import
backend/tests/auth/test_token_manager.py
JWT import switched from from jose import jwt to import jwt, so encode/decode calls now target PyJWT.
Dependency manifest and documentation updates
backend/requirements.txt, README.md, THIRD_PARTY_LICENSES.md, .claude/rules/backend/auth-security.md
python-jose[cryptography] replaced with PyJWT[crypto]==2.13.0 in requirements; README, license list, and rules doc updated to reflect PyJWT usage.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

  • yusuke0610/devforge#464: Both PRs modify backend/tests/auth/test_token_manager.py, updating JWT handling/imports and consolidating JWT claim assertions.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly matches the main change: migrating JWT auth from python-jose to PyJWT to address the ecdsa vulnerability.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch refactor/replace-python-jose-with-pyjwt

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@yusuke0610
yusuke0610 merged commit f0917a7 into mainJul 8, 2026
24 checks passed
@yusuke0610
yusuke0610 deleted the refactor/replace-python-jose-with-pyjwt branch July 20, 2026 12:25
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

authbackendバックエンドdocumentationImprovements or additions to documentationrefactorリファクタリングtestテスト追加・修正

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@yusuke0610
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

refactor(auth): JWT ライブラリを python-jose から PyJWT へ移行し ecdsa 脆弱性を解消 - #481

Merged
yusuke0610 merged 1 commit into
mainfrom
refactor/replace-python-jose-with-pyjwt
Jul 8, 2026
Merged

refactor(auth): JWT ライブラリを python-jose から PyJWT へ移行し ecdsa 脆弱性を解消#481
yusuke0610 merged 1 commit into
mainfrom
refactor/replace-python-jose-with-pyjwt

Conversation

@yusuke0610

@yusuke0610yusuke0610 commented Jul 8, 2026

Copy link
Copy Markdown
Owner

背景

python-jose[cryptography] の推移的依存 ecdsa 0.19.2修正版の出ない脆弱性PYSEC-2026-1325(Minerva タイミング攻撃・P-256、CVSS 7.4)が存在し、CI の pip-audit全オープン PR・main 共通で fail していた。メンテナが「サイドチャネルは対象外」として修正しない方針のため requirements.txt の「バージョン引き上げ」運用が使えない。

対応

DevForge の JWT は RS256 のみapp/core/security/auth.py)で python-jose は cryptography バックエンドを使い、ecdsa 経路(ecdsa.SigningKey.sign_digest())は一切通らない。そのため脆弱性は実質非該当だが、依存ツリーから消すのが最もクリーンと判断し PyJWT[crypto] へ移行して ecdsa 依存自体を除去する。

  • auth.py: jose.JWTErrorjwt.PyJWTError(RS256 の署名・検証挙動は不変)
  • requirements.txt: python-jose[cryptography]==3.5.0PyJWT[crypto]==2.13.0
  • THIRD_PARTY_LICENSES.mdmake licenses で再生成
  • README.md / .claude/rules/backend/auth-security.md の JWT ライブラリ表記を更新

検証

  • pip-audit -r requirements.txtNo known vulnerabilities found(ecdsa がツリーから消失)
  • auth / security テスト 150 件 pass(HS256→RS256 拒否テスト含む)
  • make ci full green

影響範囲

このマージ後、blocker が解消されるため滞留中の Renovate PR(#466 / #467 / #468 / #470)も緑化してマージ可能になる。

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores

    • Updated the app’s authentication implementation to use a different JWT library, with no expected change to login or token behavior.
    • Refreshed related dependency and license listings to match the current setup.
  • Documentation

    • Aligned the README and internal guidance with the updated authentication stack.

python-jose の推移的依存 ecdsa 0.19.2 に修正版の出ない脆弱性
(PYSEC-2026-1325 / Minerva タイミング攻撃・P-256)があり、pip-audit が
全 PR・main 共通で fail していた。DevForge の JWT は RS256 のみで
cryptography バックエンドを使い ecdsa 経路は未使用のため、PyJWT[crypto]
へ移行して ecdsa 依存自体を除去する。
- auth.py: jose.JWTError → jwt.PyJWTError(RS256 の署名・検証挙動は不変)
- requirements.txt: python-jose[cryptography]==3.5.0 → PyJWT[crypto]==2.13.0
- THIRD_PARTY_LICENSES.md を make licenses で再生成
- README / auth-security.md の JWT ライブラリ表記を更新
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@github-actionsgithub-actionsBot added auth refactor リファクタリング documentation Improvements or additions to documentation backend バックエンド test テスト追加・修正 labels Jul 8, 2026
@coderabbitai

coderabbitaiBot commented Jul 8, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: a381b839-65b5-48d7-b1ce-a1bc15633d12

📥 Commits

Reviewing files that changed from the base of the PR and between 114f801 and a42100c.

📒 Files selected for processing (6)
  • .claude/rules/backend/auth-security.md
  • README.md
  • THIRD_PARTY_LICENSES.md
  • backend/app/core/security/auth.py
  • backend/requirements.txt
  • backend/tests/auth/test_token_manager.py

📝 Walkthrough

Walkthrough

The JWT library dependency is migrated from python-jose to PyJWT throughout the backend. The auth module's import and exception handling are updated to use jwt.PyJWTError, tests are adjusted, and requirements.txt, README, third-party license list, and internal rules documentation are updated accordingly.

Changes

JWT Library Migration

Layer / File(s)Summary
Core auth logic switched to PyJWT
backend/app/core/security/auth.py
Import changed from jose's jwt to direct import jwt; exception handling updated from JWTError to jwt.PyJWTError in key pair validation and token decoding, preserving the same 401 failure path.
Test suite updated for PyJWT import
backend/tests/auth/test_token_manager.py
JWT import switched from from jose import jwt to import jwt, so encode/decode calls now target PyJWT.
Dependency manifest and documentation updates
backend/requirements.txt, README.md, THIRD_PARTY_LICENSES.md, .claude/rules/backend/auth-security.md
python-jose[cryptography] replaced with PyJWT[crypto]==2.13.0 in requirements; README, license list, and rules doc updated to reflect PyJWT usage.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

  • yusuke0610/devforge#464: Both PRs modify backend/tests/auth/test_token_manager.py, updating JWT handling/imports and consolidating JWT claim assertions.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly matches the main change: migrating JWT auth from python-jose to PyJWT to address the ecdsa vulnerability.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch refactor/replace-python-jose-with-pyjwt

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@yusuke0610
yusuke0610 merged commit f0917a7 into mainJul 8, 2026
24 checks passed
@yusuke0610
yusuke0610 deleted the refactor/replace-python-jose-with-pyjwt branch July 20, 2026 12:25
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

authbackendバックエンドdocumentationImprovements or additions to documentationrefactorリファクタリングtestテスト追加・修正

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@yusuke0610
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

refactor(auth): JWT ライブラリを python-jose から PyJWT へ移行し ecdsa 脆弱性を解消 - #481

Merged
yusuke0610 merged 1 commit into
mainfrom
refactor/replace-python-jose-with-pyjwt
Jul 8, 2026
Merged

refactor(auth): JWT ライブラリを python-jose から PyJWT へ移行し ecdsa 脆弱性を解消#481
yusuke0610 merged 1 commit into
mainfrom
refactor/replace-python-jose-with-pyjwt

Conversation

@yusuke0610

@yusuke0610yusuke0610 commented Jul 8, 2026

Copy link
Copy Markdown
Owner

背景

python-jose[cryptography] の推移的依存 ecdsa 0.19.2修正版の出ない脆弱性PYSEC-2026-1325(Minerva タイミング攻撃・P-256、CVSS 7.4)が存在し、CI の pip-audit全オープン PR・main 共通で fail していた。メンテナが「サイドチャネルは対象外」として修正しない方針のため requirements.txt の「バージョン引き上げ」運用が使えない。

対応

DevForge の JWT は RS256 のみapp/core/security/auth.py)で python-jose は cryptography バックエンドを使い、ecdsa 経路(ecdsa.SigningKey.sign_digest())は一切通らない。そのため脆弱性は実質非該当だが、依存ツリーから消すのが最もクリーンと判断し PyJWT[crypto] へ移行して ecdsa 依存自体を除去する。

  • auth.py: jose.JWTErrorjwt.PyJWTError(RS256 の署名・検証挙動は不変)
  • requirements.txt: python-jose[cryptography]==3.5.0PyJWT[crypto]==2.13.0
  • THIRD_PARTY_LICENSES.mdmake licenses で再生成
  • README.md / .claude/rules/backend/auth-security.md の JWT ライブラリ表記を更新

検証

  • pip-audit -r requirements.txtNo known vulnerabilities found(ecdsa がツリーから消失)
  • auth / security テスト 150 件 pass(HS256→RS256 拒否テスト含む)
  • make ci full green

影響範囲

このマージ後、blocker が解消されるため滞留中の Renovate PR(#466 / #467 / #468 / #470)も緑化してマージ可能になる。

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores

    • Updated the app’s authentication implementation to use a different JWT library, with no expected change to login or token behavior.
    • Refreshed related dependency and license listings to match the current setup.
  • Documentation

    • Aligned the README and internal guidance with the updated authentication stack.

python-jose の推移的依存 ecdsa 0.19.2 に修正版の出ない脆弱性
(PYSEC-2026-1325 / Minerva タイミング攻撃・P-256)があり、pip-audit が
全 PR・main 共通で fail していた。DevForge の JWT は RS256 のみで
cryptography バックエンドを使い ecdsa 経路は未使用のため、PyJWT[crypto]
へ移行して ecdsa 依存自体を除去する。
- auth.py: jose.JWTError → jwt.PyJWTError(RS256 の署名・検証挙動は不変)
- requirements.txt: python-jose[cryptography]==3.5.0 → PyJWT[crypto]==2.13.0
- THIRD_PARTY_LICENSES.md を make licenses で再生成
- README / auth-security.md の JWT ライブラリ表記を更新
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@github-actionsgithub-actionsBot added auth refactor リファクタリング documentation Improvements or additions to documentation backend バックエンド test テスト追加・修正 labels Jul 8, 2026
@coderabbitai

coderabbitaiBot commented Jul 8, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: a381b839-65b5-48d7-b1ce-a1bc15633d12

📥 Commits

Reviewing files that changed from the base of the PR and between 114f801 and a42100c.

📒 Files selected for processing (6)
  • .claude/rules/backend/auth-security.md
  • README.md
  • THIRD_PARTY_LICENSES.md
  • backend/app/core/security/auth.py
  • backend/requirements.txt
  • backend/tests/auth/test_token_manager.py

📝 Walkthrough

Walkthrough

The JWT library dependency is migrated from python-jose to PyJWT throughout the backend. The auth module's import and exception handling are updated to use jwt.PyJWTError, tests are adjusted, and requirements.txt, README, third-party license list, and internal rules documentation are updated accordingly.

Changes

JWT Library Migration

Layer / File(s)Summary
Core auth logic switched to PyJWT
backend/app/core/security/auth.py
Import changed from jose's jwt to direct import jwt; exception handling updated from JWTError to jwt.PyJWTError in key pair validation and token decoding, preserving the same 401 failure path.
Test suite updated for PyJWT import
backend/tests/auth/test_token_manager.py
JWT import switched from from jose import jwt to import jwt, so encode/decode calls now target PyJWT.
Dependency manifest and documentation updates
backend/requirements.txt, README.md, THIRD_PARTY_LICENSES.md, .claude/rules/backend/auth-security.md
python-jose[cryptography] replaced with PyJWT[crypto]==2.13.0 in requirements; README, license list, and rules doc updated to reflect PyJWT usage.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

  • yusuke0610/devforge#464: Both PRs modify backend/tests/auth/test_token_manager.py, updating JWT handling/imports and consolidating JWT claim assertions.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly matches the main change: migrating JWT auth from python-jose to PyJWT to address the ecdsa vulnerability.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch refactor/replace-python-jose-with-pyjwt

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@yusuke0610
yusuke0610 merged commit f0917a7 into mainJul 8, 2026
24 checks passed
@yusuke0610
yusuke0610 deleted the refactor/replace-python-jose-with-pyjwt branch July 20, 2026 12:25
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

authbackendバックエンドdocumentationImprovements or additions to documentationrefactorリファクタリングtestテスト追加・修正

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@yusuke0610
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

refactor(auth): JWT ライブラリを python-jose から PyJWT へ移行し ecdsa 脆弱性を解消 - #481

Merged
yusuke0610 merged 1 commit into
mainfrom
refactor/replace-python-jose-with-pyjwt
Jul 8, 2026
Merged

refactor(auth): JWT ライブラリを python-jose から PyJWT へ移行し ecdsa 脆弱性を解消#481
yusuke0610 merged 1 commit into
mainfrom
refactor/replace-python-jose-with-pyjwt

Conversation

@yusuke0610

@yusuke0610yusuke0610 commented Jul 8, 2026

Copy link
Copy Markdown
Owner

背景

python-jose[cryptography] の推移的依存 ecdsa 0.19.2修正版の出ない脆弱性PYSEC-2026-1325(Minerva タイミング攻撃・P-256、CVSS 7.4)が存在し、CI の pip-audit全オープン PR・main 共通で fail していた。メンテナが「サイドチャネルは対象外」として修正しない方針のため requirements.txt の「バージョン引き上げ」運用が使えない。

対応

DevForge の JWT は RS256 のみapp/core/security/auth.py)で python-jose は cryptography バックエンドを使い、ecdsa 経路(ecdsa.SigningKey.sign_digest())は一切通らない。そのため脆弱性は実質非該当だが、依存ツリーから消すのが最もクリーンと判断し PyJWT[crypto] へ移行して ecdsa 依存自体を除去する。

  • auth.py: jose.JWTErrorjwt.PyJWTError(RS256 の署名・検証挙動は不変)
  • requirements.txt: python-jose[cryptography]==3.5.0PyJWT[crypto]==2.13.0
  • THIRD_PARTY_LICENSES.mdmake licenses で再生成
  • README.md / .claude/rules/backend/auth-security.md の JWT ライブラリ表記を更新

検証

  • pip-audit -r requirements.txtNo known vulnerabilities found(ecdsa がツリーから消失)
  • auth / security テスト 150 件 pass(HS256→RS256 拒否テスト含む)
  • make ci full green

影響範囲

このマージ後、blocker が解消されるため滞留中の Renovate PR(#466 / #467 / #468 / #470)も緑化してマージ可能になる。

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores

    • Updated the app’s authentication implementation to use a different JWT library, with no expected change to login or token behavior.
    • Refreshed related dependency and license listings to match the current setup.
  • Documentation

    • Aligned the README and internal guidance with the updated authentication stack.

python-jose の推移的依存 ecdsa 0.19.2 に修正版の出ない脆弱性
(PYSEC-2026-1325 / Minerva タイミング攻撃・P-256)があり、pip-audit が
全 PR・main 共通で fail していた。DevForge の JWT は RS256 のみで
cryptography バックエンドを使い ecdsa 経路は未使用のため、PyJWT[crypto]
へ移行して ecdsa 依存自体を除去する。
- auth.py: jose.JWTError → jwt.PyJWTError(RS256 の署名・検証挙動は不変)
- requirements.txt: python-jose[cryptography]==3.5.0 → PyJWT[crypto]==2.13.0
- THIRD_PARTY_LICENSES.md を make licenses で再生成
- README / auth-security.md の JWT ライブラリ表記を更新
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@github-actionsgithub-actionsBot added auth refactor リファクタリング documentation Improvements or additions to documentation backend バックエンド test テスト追加・修正 labels Jul 8, 2026
@coderabbitai

coderabbitaiBot commented Jul 8, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: a381b839-65b5-48d7-b1ce-a1bc15633d12

📥 Commits

Reviewing files that changed from the base of the PR and between 114f801 and a42100c.

📒 Files selected for processing (6)
  • .claude/rules/backend/auth-security.md
  • README.md
  • THIRD_PARTY_LICENSES.md
  • backend/app/core/security/auth.py
  • backend/requirements.txt
  • backend/tests/auth/test_token_manager.py

📝 Walkthrough

Walkthrough

The JWT library dependency is migrated from python-jose to PyJWT throughout the backend. The auth module's import and exception handling are updated to use jwt.PyJWTError, tests are adjusted, and requirements.txt, README, third-party license list, and internal rules documentation are updated accordingly.

Changes

JWT Library Migration

Layer / File(s)Summary
Core auth logic switched to PyJWT
backend/app/core/security/auth.py
Import changed from jose's jwt to direct import jwt; exception handling updated from JWTError to jwt.PyJWTError in key pair validation and token decoding, preserving the same 401 failure path.
Test suite updated for PyJWT import
backend/tests/auth/test_token_manager.py
JWT import switched from from jose import jwt to import jwt, so encode/decode calls now target PyJWT.
Dependency manifest and documentation updates
backend/requirements.txt, README.md, THIRD_PARTY_LICENSES.md, .claude/rules/backend/auth-security.md
python-jose[cryptography] replaced with PyJWT[crypto]==2.13.0 in requirements; README, license list, and rules doc updated to reflect PyJWT usage.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

  • yusuke0610/devforge#464: Both PRs modify backend/tests/auth/test_token_manager.py, updating JWT handling/imports and consolidating JWT claim assertions.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly matches the main change: migrating JWT auth from python-jose to PyJWT to address the ecdsa vulnerability.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch refactor/replace-python-jose-with-pyjwt

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@yusuke0610
yusuke0610 merged commit f0917a7 into mainJul 8, 2026
24 checks passed
@yusuke0610
yusuke0610 deleted the refactor/replace-python-jose-with-pyjwt branch July 20, 2026 12:25
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

authbackendバックエンドdocumentationImprovements or additions to documentationrefactorリファクタリングtestテスト追加・修正

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@yusuke0610
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

refactor(auth): JWT ライブラリを python-jose から PyJWT へ移行し ecdsa 脆弱性を解消 - #481

Merged
yusuke0610 merged 1 commit into
mainfrom
refactor/replace-python-jose-with-pyjwt
Jul 8, 2026
Merged

refactor(auth): JWT ライブラリを python-jose から PyJWT へ移行し ecdsa 脆弱性を解消#481
yusuke0610 merged 1 commit into
mainfrom
refactor/replace-python-jose-with-pyjwt

Conversation

@yusuke0610

@yusuke0610yusuke0610 commented Jul 8, 2026

Copy link
Copy Markdown
Owner

背景

python-jose[cryptography] の推移的依存 ecdsa 0.19.2修正版の出ない脆弱性PYSEC-2026-1325(Minerva タイミング攻撃・P-256、CVSS 7.4)が存在し、CI の pip-audit全オープン PR・main 共通で fail していた。メンテナが「サイドチャネルは対象外」として修正しない方針のため requirements.txt の「バージョン引き上げ」運用が使えない。

対応

DevForge の JWT は RS256 のみapp/core/security/auth.py)で python-jose は cryptography バックエンドを使い、ecdsa 経路(ecdsa.SigningKey.sign_digest())は一切通らない。そのため脆弱性は実質非該当だが、依存ツリーから消すのが最もクリーンと判断し PyJWT[crypto] へ移行して ecdsa 依存自体を除去する。

  • auth.py: jose.JWTErrorjwt.PyJWTError(RS256 の署名・検証挙動は不変)
  • requirements.txt: python-jose[cryptography]==3.5.0PyJWT[crypto]==2.13.0
  • THIRD_PARTY_LICENSES.mdmake licenses で再生成
  • README.md / .claude/rules/backend/auth-security.md の JWT ライブラリ表記を更新

検証

  • pip-audit -r requirements.txtNo known vulnerabilities found(ecdsa がツリーから消失)
  • auth / security テスト 150 件 pass(HS256→RS256 拒否テスト含む)
  • make ci full green

影響範囲

このマージ後、blocker が解消されるため滞留中の Renovate PR(#466 / #467 / #468 / #470)も緑化してマージ可能になる。

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores

    • Updated the app’s authentication implementation to use a different JWT library, with no expected change to login or token behavior.
    • Refreshed related dependency and license listings to match the current setup.
  • Documentation

    • Aligned the README and internal guidance with the updated authentication stack.

python-jose の推移的依存 ecdsa 0.19.2 に修正版の出ない脆弱性
(PYSEC-2026-1325 / Minerva タイミング攻撃・P-256)があり、pip-audit が
全 PR・main 共通で fail していた。DevForge の JWT は RS256 のみで
cryptography バックエンドを使い ecdsa 経路は未使用のため、PyJWT[crypto]
へ移行して ecdsa 依存自体を除去する。
- auth.py: jose.JWTError → jwt.PyJWTError(RS256 の署名・検証挙動は不変)
- requirements.txt: python-jose[cryptography]==3.5.0 → PyJWT[crypto]==2.13.0
- THIRD_PARTY_LICENSES.md を make licenses で再生成
- README / auth-security.md の JWT ライブラリ表記を更新
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@github-actionsgithub-actionsBot added auth refactor リファクタリング documentation Improvements or additions to documentation backend バックエンド test テスト追加・修正 labels Jul 8, 2026
@coderabbitai

coderabbitaiBot commented Jul 8, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: a381b839-65b5-48d7-b1ce-a1bc15633d12

📥 Commits

Reviewing files that changed from the base of the PR and between 114f801 and a42100c.

📒 Files selected for processing (6)
  • .claude/rules/backend/auth-security.md
  • README.md
  • THIRD_PARTY_LICENSES.md
  • backend/app/core/security/auth.py
  • backend/requirements.txt
  • backend/tests/auth/test_token_manager.py

📝 Walkthrough

Walkthrough

The JWT library dependency is migrated from python-jose to PyJWT throughout the backend. The auth module's import and exception handling are updated to use jwt.PyJWTError, tests are adjusted, and requirements.txt, README, third-party license list, and internal rules documentation are updated accordingly.

Changes

JWT Library Migration

Layer / File(s)Summary
Core auth logic switched to PyJWT
backend/app/core/security/auth.py
Import changed from jose's jwt to direct import jwt; exception handling updated from JWTError to jwt.PyJWTError in key pair validation and token decoding, preserving the same 401 failure path.
Test suite updated for PyJWT import
backend/tests/auth/test_token_manager.py
JWT import switched from from jose import jwt to import jwt, so encode/decode calls now target PyJWT.
Dependency manifest and documentation updates
backend/requirements.txt, README.md, THIRD_PARTY_LICENSES.md, .claude/rules/backend/auth-security.md
python-jose[cryptography] replaced with PyJWT[crypto]==2.13.0 in requirements; README, license list, and rules doc updated to reflect PyJWT usage.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

  • yusuke0610/devforge#464: Both PRs modify backend/tests/auth/test_token_manager.py, updating JWT handling/imports and consolidating JWT claim assertions.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly matches the main change: migrating JWT auth from python-jose to PyJWT to address the ecdsa vulnerability.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch refactor/replace-python-jose-with-pyjwt

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@yusuke0610
yusuke0610 merged commit f0917a7 into mainJul 8, 2026
24 checks passed
@yusuke0610
yusuke0610 deleted the refactor/replace-python-jose-with-pyjwt branch July 20, 2026 12:25
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

authbackendバックエンドdocumentationImprovements or additions to documentationrefactorリファクタリングtestテスト追加・修正

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@yusuke0610
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

refactor(auth): JWT ライブラリを python-jose から PyJWT へ移行し ecdsa 脆弱性を解消 - #481

Merged
yusuke0610 merged 1 commit into
mainfrom
refactor/replace-python-jose-with-pyjwt
Jul 8, 2026
Merged

refactor(auth): JWT ライブラリを python-jose から PyJWT へ移行し ecdsa 脆弱性を解消#481
yusuke0610 merged 1 commit into
mainfrom
refactor/replace-python-jose-with-pyjwt

Conversation

@yusuke0610

@yusuke0610yusuke0610 commented Jul 8, 2026

Copy link
Copy Markdown
Owner

背景

python-jose[cryptography] の推移的依存 ecdsa 0.19.2修正版の出ない脆弱性PYSEC-2026-1325(Minerva タイミング攻撃・P-256、CVSS 7.4)が存在し、CI の pip-audit全オープン PR・main 共通で fail していた。メンテナが「サイドチャネルは対象外」として修正しない方針のため requirements.txt の「バージョン引き上げ」運用が使えない。

対応

DevForge の JWT は RS256 のみapp/core/security/auth.py)で python-jose は cryptography バックエンドを使い、ecdsa 経路(ecdsa.SigningKey.sign_digest())は一切通らない。そのため脆弱性は実質非該当だが、依存ツリーから消すのが最もクリーンと判断し PyJWT[crypto] へ移行して ecdsa 依存自体を除去する。

  • auth.py: jose.JWTErrorjwt.PyJWTError(RS256 の署名・検証挙動は不変)
  • requirements.txt: python-jose[cryptography]==3.5.0PyJWT[crypto]==2.13.0
  • THIRD_PARTY_LICENSES.mdmake licenses で再生成
  • README.md / .claude/rules/backend/auth-security.md の JWT ライブラリ表記を更新

検証

  • pip-audit -r requirements.txtNo known vulnerabilities found(ecdsa がツリーから消失)
  • auth / security テスト 150 件 pass(HS256→RS256 拒否テスト含む)
  • make ci full green

影響範囲

このマージ後、blocker が解消されるため滞留中の Renovate PR(#466 / #467 / #468 / #470)も緑化してマージ可能になる。

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores

    • Updated the app’s authentication implementation to use a different JWT library, with no expected change to login or token behavior.
    • Refreshed related dependency and license listings to match the current setup.
  • Documentation

    • Aligned the README and internal guidance with the updated authentication stack.

python-jose の推移的依存 ecdsa 0.19.2 に修正版の出ない脆弱性
(PYSEC-2026-1325 / Minerva タイミング攻撃・P-256)があり、pip-audit が
全 PR・main 共通で fail していた。DevForge の JWT は RS256 のみで
cryptography バックエンドを使い ecdsa 経路は未使用のため、PyJWT[crypto]
へ移行して ecdsa 依存自体を除去する。
- auth.py: jose.JWTError → jwt.PyJWTError(RS256 の署名・検証挙動は不変)
- requirements.txt: python-jose[cryptography]==3.5.0 → PyJWT[crypto]==2.13.0
- THIRD_PARTY_LICENSES.md を make licenses で再生成
- README / auth-security.md の JWT ライブラリ表記を更新
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@github-actionsgithub-actionsBot added auth refactor リファクタリング documentation Improvements or additions to documentation backend バックエンド test テスト追加・修正 labels Jul 8, 2026
@coderabbitai

coderabbitaiBot commented Jul 8, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: a381b839-65b5-48d7-b1ce-a1bc15633d12

📥 Commits

Reviewing files that changed from the base of the PR and between 114f801 and a42100c.

📒 Files selected for processing (6)
  • .claude/rules/backend/auth-security.md
  • README.md
  • THIRD_PARTY_LICENSES.md
  • backend/app/core/security/auth.py
  • backend/requirements.txt
  • backend/tests/auth/test_token_manager.py

📝 Walkthrough

Walkthrough

The JWT library dependency is migrated from python-jose to PyJWT throughout the backend. The auth module's import and exception handling are updated to use jwt.PyJWTError, tests are adjusted, and requirements.txt, README, third-party license list, and internal rules documentation are updated accordingly.

Changes

JWT Library Migration

Layer / File(s)Summary
Core auth logic switched to PyJWT
backend/app/core/security/auth.py
Import changed from jose's jwt to direct import jwt; exception handling updated from JWTError to jwt.PyJWTError in key pair validation and token decoding, preserving the same 401 failure path.
Test suite updated for PyJWT import
backend/tests/auth/test_token_manager.py
JWT import switched from from jose import jwt to import jwt, so encode/decode calls now target PyJWT.
Dependency manifest and documentation updates
backend/requirements.txt, README.md, THIRD_PARTY_LICENSES.md, .claude/rules/backend/auth-security.md
python-jose[cryptography] replaced with PyJWT[crypto]==2.13.0 in requirements; README, license list, and rules doc updated to reflect PyJWT usage.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

  • yusuke0610/devforge#464: Both PRs modify backend/tests/auth/test_token_manager.py, updating JWT handling/imports and consolidating JWT claim assertions.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly matches the main change: migrating JWT auth from python-jose to PyJWT to address the ecdsa vulnerability.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch refactor/replace-python-jose-with-pyjwt

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@yusuke0610
yusuke0610 merged commit f0917a7 into mainJul 8, 2026
24 checks passed
@yusuke0610
yusuke0610 deleted the refactor/replace-python-jose-with-pyjwt branch July 20, 2026 12:25
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

authbackendバックエンドdocumentationImprovements or additions to documentationrefactorリファクタリングtestテスト追加・修正

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@yusuke0610