Skip to content

bump jwt from 2.10.3 to 3.2.0 - #8039

Merged
david-yz-liu merged 4 commits into
MarkUsProject:masterfrom
donny-wong:bump-jwt-3.2.0
Jul 3, 2026
Merged

bump jwt from 2.10.3 to 3.2.0#8039
david-yz-liu merged 4 commits into
MarkUsProject:masterfrom
donny-wong:bump-jwt-3.2.0

Conversation

@donny-wong

@donny-wong donny-wong commented Jul 2, 2026

Copy link
Copy Markdown
Contributor

Proposed Changes

(Describe your changes here. Also describe the motivation for your changes: what problem do they solve, or how do they improve the application or codebase? If this pull request fixes an open issue, use a keyword to link this pull request to the issue.)

Manually bump jwt gem from 2.10.3 → 3.2.0. Since jwt is unpinned in the Gemfile, this is a
Gemfile.lock-only change.

3.2.0 is the current latest release. Relevant points from its changelog:

  • Carries the fix for GHSA-c32j-vqhx-rx3x - rejecting nil/empty HMAC keys when signing and verifying. As assessed in the Dependabot bump build(deps): bump jwt from 2.10.1 to 2.10.3 #7959, this is an HMAC vulnerability, and MarkUs signs and verifies exclusively with RSA/RS256, so the vulnerable path was never reachable - but moving to the patched release keeps us current.
  • The openssl 4.0 gem compatibility fix does not apply here: MarkUs does not bundle the standalone openssl gem (it is absent from Gemfile.lock) and instead relies on Ruby's stdlib OpenSSL. RSA/RS256 was confirmed working at runtime.
  • Remaining entries are HMAC-only (enforce_hmac_key_length), CI-only (Ruby 4.0 test matrix), or defensive hardening (type error on non-JSON token headers) - none affect the RSA/RS256/JWKS paths MarkUs uses.

Major version (3.0) breaking-change review

  • HMAC/EdDSA changes (jwt-eddsa split, rbnacl removal, HS512256 drop) — irrelevant to RSA.
  • RSA keys must be ≥ 2048 bits — satisfied by construction: rails markus:lti_key hardcodes OpenSSL::PKey::RSA.new(2048).
  • Verify-before-payload — our decode verifies before reading claims (no unverified payload access).
  • Stricter RFC 4648 base64 decoding — Canvas tokens are properly encoded and decode cleanly under the stricter rule.
  • Custom-algorithm interface change — N/A; MarkUs uses only the built-in RS256 algorithm, no custom algorithms defined.

Tests:

  • Ran the full LTI spec suite successfully.
  • Successful testing on local Canvas and MarkUs.
Screenshots of your changes (if applicable)

Type of Change

(Write an X or a brief description next to the type or types that best describe your changes.)

Type Applies?
🚨 Breaking change (fix or feature that would cause existing functionality to change)
New feature (non-breaking change that adds functionality)
🐛 Bug fix (non-breaking change that fixes an issue)
🎨 User interface change (change to user interface; provide screenshots)
♻️ Refactoring (internal change to codebase, without changing functionality)
🚦 Test update (change that only adds or modifies tests)
📦 Dependency update (change that updates a dependency) x
📖 Documentation update (change that updates documentation)
🔧 Internal (change that only affects developers or continuous integration)

Checklist

(Complete each of the following items for your pull request. Indicate that you have completed an item by changing the [ ] into a [x] in the raw text, or by clicking on the checkbox in the rendered description on GitHub.)

Before opening your pull request:

  • I have performed a self-review of my changes.
    • Check that all changed files included in this pull request are intentional changes.
    • Check that all changes are relevant to the purpose of this pull request, as described above.
  • I have added tests for my changes, if applicable.
    • This is required for all bug fixes and new features.
  • I have updated the project documentation, if applicable.
    • This is required for new features.
  • If this is my first contribution, I have added myself to the list of contributors.

After opening your pull request:

  • I have updated the project Changelog (this is required for all changes).
  • I have verified that the pre-commit.ci checks have passed.
  • I have verified that the CI tests have passed.
  • I have reviewed the test coverage changes reported by Coveralls.
  • I have requested a review from a project maintainer.

Questions and Comments

(Include any questions or comments you have regarding your changes.)

@coveralls

Copy link
Copy Markdown
Collaborator

Coverage Report for CI Build 28621447237

Coverage remained the same at 90.251%

Details

  • Coverage remained the same as the base build.
  • Patch coverage: 1 of 1 lines across 1 file are fully covered (100%).
  • No coverage regressions found.

Uncovered Changes

No uncovered changes found.

Coverage Regressions

No coverage regressions found.


Coverage Stats

Coverage Status
Relevant Lines: 50871
Covered Lines: 46927
Line Coverage: 92.25%
Relevant Branches: 2419
Covered Branches: 1168
Branch Coverage: 48.28%
Branches in Coverage %: Yes
Coverage Strength: 127.31 hits per line

💛 - Coveralls

@donny-wong
donny-wong requested a review from Naragod July 2, 2026 21:24
@donny-wong
donny-wong requested a review from david-yz-liu July 3, 2026 12:31

@david-yz-liu david-yz-liu left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @donny-wong!

@david-yz-liu
david-yz-liu merged commit cce298a into MarkUsProject:master Jul 3, 2026
7 checks passed
@donny-wong donny-wong added this to the v2.10.1 milestone Jul 17, 2026
Naragod added a commit that referenced this pull request Jul 27, 2026
* Implement GET and PATCH /overall_comment API routes (#7963)

Closes #7708

* build(deps): bump puma from 7.2.0 to 7.2.1 (#7994)

Bumps [puma](https://github.com/puma/puma) from 7.2.0 to 7.2.1.
- [Release notes](https://github.com/puma/puma/releases)
- [Changelog](https://github.com/puma/puma/blob/main/History.md)
- [Commits](puma/puma@v7.2.0...v7.2.1)

---
updated-dependencies:
- dependency-name: puma
  dependency-version: 7.2.1
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* build(deps): bump dompurify from 3.4.0 to 3.4.9 (#8005)

Bumps [dompurify](https://github.com/cure53/DOMPurify) from 3.4.0 to 3.4.9.
- [Release notes](https://github.com/cure53/DOMPurify/releases)
- [Commits](cure53/DOMPurify@3.4.0...3.4.9)

---
updated-dependencies:
- dependency-name: dompurify
  dependency-version: 3.4.9
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Refactored SubmissionFilePanel subcomponents into functional style (#7969)

* build(deps): bump net-imap from 0.6.4 to 0.6.4.1 (#7995)

Bumps [net-imap](https://github.com/ruby/net-imap) from 0.6.4 to 0.6.4.1.
- [Release notes](https://github.com/ruby/net-imap/releases)
- [Commits](ruby/net-imap@v0.6.4...v0.6.4.1)

---
updated-dependencies:
- dependency-name: net-imap
  dependency-version: 0.6.4.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* build(deps): bump dompurify from 3.4.9 to 3.4.11 (#8009)

Bumps [dompurify](https://github.com/cure53/DOMPurify) from 3.4.9 to 3.4.11.
- [Release notes](https://github.com/cure53/DOMPurify/releases)
- [Commits](cure53/DOMPurify@3.4.9...3.4.11)

---
updated-dependencies:
- dependency-name: dompurify
  dependency-version: 3.4.11
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Added missing NOT NULL db constraints and presence validations (#7965)

Issues detected by active_record_doctor

* build(deps): bump nokogiri from 1.19.3 to 1.19.4 (#8010)

Bumps [nokogiri](https://github.com/sparklemotion/nokogiri) from 1.19.3 to 1.19.4.
- [Release notes](https://github.com/sparklemotion/nokogiri/releases)
- [Changelog](https://github.com/sparklemotion/nokogiri/blob/main/CHANGELOG.md)
- [Commits](sparklemotion/nokogiri@v1.19.3...v1.19.4)

---
updated-dependencies:
- dependency-name: nokogiri
  dependency-version: 1.19.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* build(deps-dev): bump ws from 8.18.3 to 8.21.1 (#8058)

Bumps [ws](https://github.com/websockets/ws) from 8.18.3 to 8.21.1.
- [Release notes](https://github.com/websockets/ws/releases)
- [Commits](websockets/ws@8.18.3...8.21.1)

---
updated-dependencies:
- dependency-name: ws
  dependency-version: 8.21.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Added case sensitivity to group search (#7938)

This adds a new caseSensitiveTextFilter table component for doing case-sensitive search.

* build(deps): bump concurrent-ruby from 1.3.6 to 1.3.7 (#8011)

Bumps [concurrent-ruby](https://github.com/ruby-concurrency/concurrent-ruby) from 1.3.6 to 1.3.7.
- [Release notes](https://github.com/ruby-concurrency/concurrent-ruby/releases)
- [Changelog](https://github.com/ruby-concurrency/concurrent-ruby/blob/master/CHANGELOG.md)
- [Commits](ruby-concurrency/concurrent-ruby@v1.3.6...v1.3.7)

---
updated-dependencies:
- dependency-name: concurrent-ruby
  dependency-version: 1.3.7
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Refactored group creation to set group_name and repo_name pre-validation (#7975)

Also add NOT NULL constraint to groups.group_name column

* Simplified Chart.js usage (#7987)

* Migrated MarkingSchemesTable to React Table v8 (#7985)

* Fixed merge commits being incorrectly attributed as latest submission (#7988)

When an instructor cloned a student repo, made a local commit, then merged and
pushed, the merge commit was treated as the latest submission for the student's
files. This inflated late penalties and showed the instructor's name as author.

`entry_changed?` returned true for a merge commit whenever the file differed from
*any* parent — including the instructor's branch that simply didn't have the file
yet. The fix: for merge commits (2+ parents), only return true when the result
differs from *all* parents. If the merged content matches at least one parent the
merge was trivial for that path and should not be counted as a new modification.

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>

* Refactored criterion keyboard navigation (#7989)

* Moved criterion and level keyboard handlers into React components (MarksPanel and RubricCrtierionInput)
* Fixed keyboard criterion navigation when flexible/checkbox inputs were focused
* Ensured criterion navigation causes selected criterion to scroll into view

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>

* Fixed navbar MarkUs logo link URL on mobile (#7990)

* Added confirmation when uploading scans for a template with no divisions (#7993)

* Fixed tester spec upload when spec contains non-existent criterion (#7998)

Closes #7528

* Migrated SummaryPanel marks chart modal to use react-modal (#7996)

* Added release process automation scripts (#7914)

* Fixed SVG rendering by converting base64 SVG data URIs to inline <svg> (#8001)

* Added pagination to Admin Users table for performance (#7997)

* Added confirm dialog when a student submits during late period (#8003)

* Reorganized locale strings from config/locales/en.yml (#8012)

* Used native HTML required validation on modal upload inputs (#8016)

* Refactored group creation job updates to use websockets (#8020)

* Updated database indexes (#8018)

- Enforce model uniqueness validations
- Remove redundant indexes

These were detected by active_record_doctor:missing_unique_indexes and active_record_doctor:extraneous_indexes.

* Migrated graders_manager.jsx tables to react-table v8 (#8014)

* Support all annotation types in add_annotations API route (#8007)

* Fixed result annotation links to display correct file (#8017)

* Updated PDFViewer to persist PDF scroll across submissions (#8004)

* Added assignment grades upload feature (#8008)

* bump jwt from 2.10.3 to 3.2.0 (#8039)

* Fix LTI test JWK fixture to use 2048-bit key for jwt 3.0 compatibility

* Fixed selection column header checkbox in v8 tables (#8037)

* Added migrations to add missing timestamp columns and foreign key constraints (#8040)

* Fixed assignment dropdown menu redirection from Assignments#index (#8043)

* Fixed escaping of HTML annotation start_node and end_node attributes (#8064)

* update changelog with new release v2.10.1 [ci skip]

* update markus version

* Fix rubocop ArrayIntersect and spec path offenses

* [pre-commit.ci] auto fixes from pre-commit.com hooks

for more information, see https://pre-commit.ci

* Install postgresql-client-17 for CI pg_dump compatibility

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: philipkukulak <philip.kukulak@utoronto.ca>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: David Liu <david@cs.toronto.edu>
Co-authored-by: Yanzhen Chen <yanzhenchen123@gmail.com>
Co-authored-by: Muhammad <rafie.muhammad2007@gmail.com>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: Daniel Rafailov <74218740+danielrafailov1@users.noreply.github.com>
Co-authored-by: donny-wong <141858744+donny-wong@users.noreply.github.com>
Co-authored-by: Aayush Karki <147123757+akarki2005@users.noreply.github.com>
Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants