Skip to content

Drop authlib and fetch the access token with httpx - #62

Merged
vigneshwerv merged 1 commit into
devfrom
remove-authlib
Oct 1, 2026
Merged

vigneshwerv merged 1 commit into
devfrom
remove-authlib

Conversation

@varun-mohan

Copy link
Copy Markdown
Contributor

A customer's scanner flagged authlib 1.8.0, a transitive dependency of this SDK, for CVE-2026-96760 (CERT/CC VU#762428). It's a JWS signature-verification bypass, rated critical, with no upstream patch. The SDK's code path never reached the vulnerable function: it only used authlib's httpx OAuth2Client.fetch_token for a client-credentials grant. Still, every customer inherits authlib's whole JOSE/OIDC surface and the scanner alerts that come with it.

This replaces authlib with a single httpx POST in fragment/client/oauth.py. It sends what authlib sent: HTTP Basic client auth (client_secret_basic) and a form body of grant_type=client_credentials and scope. poetry remove authlib also drops joserfc.

  • The token call is a one-shot request with its own short-lived httpx client. authlib also used a separate client, not the GraphQL http_client. The token is cached until expires_in, so this runs about once an hour.
  • Breaking, minor: a failed token request now raises fragment.exceptions.TokenRequestException (.error, .description) instead of authlib's OAuthError. A 5xx still raises httpx.HTTPStatusError. The oauth2_client attribute is gone. Both changes are in the changelog under Unreleased. I'd release this as 1.5.0.
  • fragment/sdk/, fragment/sync_sdk/ and the snapshot carry copies of the fragment/client/ templates and are updated to match.
  • Poetry 2.5.1 rewrote the lockfile, so a few header and formatting lines changed alongside the authlib/joserfc removal.

Testing: make lint (isort, black, mypy) and make unit pass (89 tests), and make check-snapshots is clean. New offline tests in tests/test_oauth.py cover the request shape, error handling and token caching in both clients. tests/test_packaging.py now fails if authlib reappears in the wheel's Requires-Dist. The real token exchange against the live auth endpoint has only run through the integration job here. I had no credentials locally, so that job is the check to watch.

🤖 Generated with Claude Code

authlib was only used for one client-credentials token request, but it
pulled its whole JOSE/OIDC surface into every customer's dependency tree,
along with its advisories (most recently CVE-2026-96760, unpatched). The
request is now a plain httpx POST matching what authlib sent.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@vigneshwerv
vigneshwerv merged commit b2f4c4a into dev Oct 1, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants