Authoauth2 module and php-jwt dependency issue

7 views
Skip to first unread message

Wessel, Keith

unread,
Feb 18, 2026, 5:04:10 PM (2 days ago) Feb 18
to 'Mark Boyce' via SimpleSAMLphp
Hi, all,

Unless something's changed, this message is for Patrick from Cirrus Identity.

In trying to do a fresh Docker build of SimpleSAMLphp wand loading in the authoauth2 module with composer, we're getting an error that firebase/php-jwt versions before 7.0 are insecure, but version 7.0 isn't compatible with the authoauth2 module.
- cirrusidentity/simplesamlphp-module-authoauth2[v4.0.0, ..., v4.1.0, v5.0.0, ..., v5.1.0] require firebase/php-jwt ^5.5|^6 -> found firebase/php-jwt[v5.5.0, v5.5.1, v6.0.0, ..., v6.11.1] but these were not loaded, because they are affected by security advisories ("PKSA-y2cr-5h3j-g3ys", "PKSA-2kqm-ps5x-s4f5"). Go to https://packagist.org/security-advisories/ to find advisory details.

Can we get authoauth2 updated to work with the newer version of php-jwt, please? Or is there another fix that I'm overlooking?

Thanks,
Keith

Tim van Dijen

unread,
Feb 19, 2026, 4:49:43 AM (yesterday) Feb 19
to SimpleSAMLphp
Hi Keith,

I'm not sure if Patrick reads this mailing list, so I forwarded this message to him directly.

- Tim

Op woensdag 18 februari 2026 om 23:04:10 UTC+1 schreef Keith Wessel:

Peter Schober

unread,
Feb 19, 2026, 5:40:26 AM (yesterday) Feb 19
to simple...@googlegroups.com
Wessel, Keith <kwe...@illinois.edu> [2026-02-18 23:04 CET]:
> Can we get authoauth2 updated to work with the newer version of
> php-jwt, please? Or is there another fix that I'm overlooking?

Why not just file an issue?
https://github.com/cirrusidentity/simplesamlphp-module-authoauth2/issues

-peter

Wessel, Keith

unread,
12:35 PM (24 minutes ago) 12:35 PM
to simple...@googlegroups.com
Thanks, Tim and Peter. I've created issue #110 in the module's repo.

Keith


-----Original Message-----
From: simple...@googlegroups.com <simple...@googlegroups.com> On Behalf Of Peter Schober
Sent: Thursday, February 19, 2026 4:40 AM
To: simple...@googlegroups.com
Subject: Re: [simplesamlphp-users] Authoauth2 module and php-jwt dependency issue

Wessel, Keith <kwe...@illinois.edu> [2026-02-18 23:04 CET]:
> Can we get authoauth2 updated to work with the newer version of
> php-jwt, please? Or is there another fix that I'm overlooking?

Why not just file an issue?
https://urldefense.com/v3/__https://github.com/cirrusidentity/simplesamlphp-module-authoauth2/issues__;!!DZ3fjg!-PE5oBz3VLpk1TlEunnM7zuu4zO5QcUPwZcvFu0YZ206Pz9JZNOLyUt_JXXjjBxaw4k471ERrzmMGJVGWp3mES99dWB53e4$

-peter

--
This is a mailing list for users of SimpleSAMLphp, not a support service. If you are willing to buy commercial support, please take a look here:

https://urldefense.com/v3/__https://simplesamlphp.org/support__;!!DZ3fjg!-PE5oBz3VLpk1TlEunnM7zuu4zO5QcUPwZcvFu0YZ206Pz9JZNOLyUt_JXXjjBxaw4k471ERrzmMGJVGWp3mES99OBiuIDY$

Before sending your question, make sure it is related to SimpleSAMLphp, and not your web server's configuration or any other third-party software. This mailing list cannot help with software that uses SimpleSAMLphp, only regarding SimpleSAMLphp itself.

Make sure to read the documentation:

https://urldefense.com/v3/__https://simplesamlphp.org/docs/stable/__;!!DZ3fjg!-PE5oBz3VLpk1TlEunnM7zuu4zO5QcUPwZcvFu0YZ206Pz9JZNOLyUt_JXXjjBxaw4k471ERrzmMGJVGWp3mES99wFhsYtA$

If you have an issue with SimpleSAMLphp that you cannot resolve and reading the documentation doesn't help, you are more than welcome to ask here for help. Subscribe to the list and send an email with your question. However, you will be expected to comply with some minimum, common sense standards in your questions. Please read this carefully:

https://urldefense.com/v3/__http://catb.org/*esr/faqs/smart-questions.html__;fg!!DZ3fjg!-PE5oBz3VLpk1TlEunnM7zuu4zO5QcUPwZcvFu0YZ206Pz9JZNOLyUt_JXXjjBxaw4k471ERrzmMGJVGWp3mES99EfJaFbs$
---
You received this message because you are subscribed to the Google Groups "SimpleSAMLphp" group.
To unsubscribe from this group and stop receiving emails from it, send an email to simplesamlph...@googlegroups.com.
To view this discussion visit https://urldefense.com/v3/__https://groups.google.com/d/msgid/simplesamlphp/aZbokBdJxqbtvqOj*40aco.net__;JQ!!DZ3fjg!-PE5oBz3VLpk1TlEunnM7zuu4zO5QcUPwZcvFu0YZ206Pz9JZNOLyUt_JXXjjBxaw4k471ERrzmMGJVGWp3mES99UXqvc4c$ .
Reply all
Reply to author
Forward
0 new messages