-
Lukas Eipert authored
Atlassian introduces a [change to their JWTs for Connect apps][0]. There are two types of JWT, the one being affected (Context JWT) is not utilized by us. Therefore we do not need to do any code changes in the auth logic. This change only opts in to the new security model they are rolling out on June 7th. For more details see: https://gitlab.com/gitlab-org/gitlab/-/issues/328267 [0]: https://community.developer.atlassian.com/t/action-required-atlassian-connect-vulnerability-allows-bypass-of-app-qsh-verification-via-context-jwts/47072 Changelog: security
bd02953c