James Read
James Read
This feature request becomes more important with the recent discovery of [CVE-2021-46743](https://nvd.nist.gov/vuln/detail/CVE-2021-46743) so it may be wise to drop support for previous versions but that would be a breaking change....
I had to look up what a footgun is 😆 I have taken a stab at upgrading to the recommended way. ([branch](https://github.com/JimTools/slim-jwt-auth/tree/feature/php-jwt-v6)) but this isn't perfect.
It's slightly challenging to do this upgrade, but I'm more than willing to contribute in anyway I can.
@egalley I’ve forked and released the library but it’s not an ideal solution as in includes breaking changes. And with the recent events of XZ any maintainer is going to...
I’ve updated the PR with the latest changes from upstream. Just want to reiterate merging this a BC with the way multiple algorithms/secrets are handed but that is unavoidable.
@pwoszczyk As this issue has been open for a while now I've decided to fork and release the package myself with this patch applied however it is not just a...
@tuupola yes it's not an issue! I can raise a PR if you'd like.
I guess the other alternative is you give me write access to this repo and I handle the next release.
I have a small comments, I think the readme should also be updated to remove references to PHP 7.2
@NeftaliAcosta having the middleware also try and handle error logic isn’t ideal. The ‘after’ option is designed to modify the response which gets passed to the next middleware. A better...