Browse Source

Remove nimbus shadow jar (#133602) (#133614)

This shadow jar was necessary for SecurityManager due to its use of
gson libraries. However, now that entitlements has replaced security
manager, it is no longer needed.
Ryan Ernst 1 month ago
parent
commit
0d436ead56

+ 12 - 8
x-pack/plugin/security/build.gradle

@@ -81,14 +81,7 @@ dependencies {
   // Dependencies for oidc
   api "com.nimbusds:oauth2-oidc-sdk:11.22.2"
   runtimeOnly "com.nimbusds:content-type:2.3"
-  api project(path: xpackModule('security:lib:nimbus-jose-jwt-modified'), configuration: 'shadow')
-  if (isEclipse) {
-    /*
-     * Eclipse can't pick up the shadow dependency so we point it at the unmodified version of the library
-     * so it can compile things.
-     */
-    api "com.nimbusds:nimbus-jose-jwt:10.0.2"
-  }
+  api "com.nimbusds:nimbus-jose-jwt:10.0.2"
   api "com.nimbusds:lang-tag:1.7"
   api "com.sun.mail:jakarta.mail:1.6.3"
   api "net.jcip:jcip-annotations:1.0"
@@ -185,6 +178,7 @@ tasks.named("dependencyLicenses").configure {
   mapping from: /bc.*/, to: 'bouncycastle'
   mapping from: /failureaccess.*/, to: 'guava'
   mapping from: 'content-type', to: 'nimbus'
+  mapping from: /nimbus.*/, to: 'nimbus'
 }
 
 tasks.named("forbiddenPatterns").configure {
@@ -387,6 +381,16 @@ tasks.named("thirdPartyAudit").configure {
     'org.bouncycastle.util.Arrays',
     'org.bouncycastle.util.io.Streams',
     'org.bouncycastle.cert.X509CertificateHolder',
+    // missing classes linked by nimbus
+    'com.google.crypto.tink.subtle.Ed25519Sign',
+    'com.google.crypto.tink.subtle.Ed25519Sign$KeyPair',
+    'com.google.crypto.tink.subtle.Ed25519Verify',
+    'com.google.crypto.tink.subtle.X25519',
+    'com.google.crypto.tink.subtle.XChaCha20Poly1305',
+    'org.bouncycastle.cert.jcajce.JcaX509CertificateHolder',
+    'org.bouncycastle.openssl.PEMKeyPair',
+    'org.bouncycastle.openssl.PEMParser',
+    'org.bouncycastle.openssl.jcajce.JcaPEMKeyConverter'
   )
 
   ignoreViolations(

+ 0 - 13
x-pack/plugin/security/lib/build.gradle

@@ -1,13 +0,0 @@
-// This build deserves an explanation. Nimbus-jose-jwt uses gson internally, which is unfriendly
-// to our usage of the security manager, to a degree that it makes the library extremely difficult
-// to work with safely. The purpose of this build is to create a version of nimbus-jose-jwt with
-// a couple classes replaced with wrappers which work with the security manager, the source files
-// in this directory.
-
-// Because we want to include the original class files so that we can reference them without
-// modification, there are a couple intermediate steps:
-// nimbus-jose-jwt-modified-part1: Create a version of the JAR in which the relevant class files are moved to a different package.
-//      This is not immediately usable as this process rewrites the rest of the JAR to "correctly" reference the new classes. So, we need to...
-// nimbus-jose-jwt-modified-part2: Create a JAR from the result of part 1 which contains *only* the relevant class files by removing everything else.
-// nimbus-jose-jwt-modified: Use the result of part 2 here, combined with the original library, so that we can use our
-//      replacement classes which wrap the original class files.

+ 0 - 29
x-pack/plugin/security/lib/nimbus-jose-jwt-modified-part1/build.gradle

@@ -1,29 +0,0 @@
-/*
- * Copyright Elasticsearch B.V. and/or licensed to Elasticsearch B.V. under one
- * or more contributor license agreements. Licensed under the Elastic License
- * 2.0; you may not use this file except in compliance with the Elastic License
- * 2.0.
- */
-
-apply plugin: 'elasticsearch.build'
-apply plugin: 'com.gradleup.shadow'
-
-// See the build.gradle file in the parent directory for an explanation of this unusual build
-
-dependencies {
-  implementation "com.nimbusds:nimbus-jose-jwt:10.0.2"
-}
-
-tasks.named('shadowJar').configure {
-  // Attempting to exclude all of the classes we *don't* move here ought to be possible per the
-  // shadowJar docs, but actually attempting to do so results in an empty JAR. May be a bug in the shadowJar plugin.
-  relocate 'com.nimbusds.jose.util.JSONObjectUtils', 'org.elasticsearch.nimbus.jose.util.JSONObjectUtils'
-  relocate 'com.nimbusds.jose.util.JSONStringUtils', 'org.elasticsearch.nimbus.jose.util.JSONStringUtils'
-}
-
-['jarHell', 'thirdPartyAudit', 'forbiddenApisMain', 'splitPackagesAudit', 'licenseHeaders'].each {
-  tasks.named(it).configure {
-    enabled = false
-  }
-}
-

+ 0 - 202
x-pack/plugin/security/lib/nimbus-jose-jwt-modified-part1/licenses/nimbus-jose-jwt-LICENSE.txt

@@ -1,202 +0,0 @@
-
-                                 Apache License
-                           Version 2.0, January 2004
-                        http://www.apache.org/licenses/
-
-   TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
-
-   1. Definitions.
-
-      "License" shall mean the terms and conditions for use, reproduction,
-      and distribution as defined by Sections 1 through 9 of this document.
-
-      "Licensor" shall mean the copyright owner or entity authorized by
-      the copyright owner that is granting the License.
-
-      "Legal Entity" shall mean the union of the acting entity and all
-      other entities that control, are controlled by, or are under common
-      control with that entity. For the purposes of this definition,
-      "control" means (i) the power, direct or indirect, to cause the
-      direction or management of such entity, whether by contract or
-      otherwise, or (ii) ownership of fifty percent (50%) or more of the
-      outstanding shares, or (iii) beneficial ownership of such entity.
-
-      "You" (or "Your") shall mean an individual or Legal Entity
-      exercising permissions granted by this License.
-
-      "Source" form shall mean the preferred form for making modifications,
-      including but not limited to software source code, documentation
-      source, and configuration files.
-
-      "Object" form shall mean any form resulting from mechanical
-      transformation or translation of a Source form, including but
-      not limited to compiled object code, generated documentation,
-      and conversions to other media types.
-
-      "Work" shall mean the work of authorship, whether in Source or
-      Object form, made available under the License, as indicated by a
-      copyright notice that is included in or attached to the work
-      (an example is provided in the Appendix below).
-
-      "Derivative Works" shall mean any work, whether in Source or Object
-      form, that is based on (or derived from) the Work and for which the
-      editorial revisions, annotations, elaborations, or other modifications
-      represent, as a whole, an original work of authorship. For the purposes
-      of this License, Derivative Works shall not include works that remain
-      separable from, or merely link (or bind by name) to the interfaces of,
-      the Work and Derivative Works thereof.
-
-      "Contribution" shall mean any work of authorship, including
-      the original version of the Work and any modifications or additions
-      to that Work or Derivative Works thereof, that is intentionally
-      submitted to Licensor for inclusion in the Work by the copyright owner
-      or by an individual or Legal Entity authorized to submit on behalf of
-      the copyright owner. For the purposes of this definition, "submitted"
-      means any form of electronic, verbal, or written communication sent
-      to the Licensor or its representatives, including but not limited to
-      communication on electronic mailing lists, source code control systems,
-      and issue tracking systems that are managed by, or on behalf of, the
-      Licensor for the purpose of discussing and improving the Work, but
-      excluding communication that is conspicuously marked or otherwise
-      designated in writing by the copyright owner as "Not a Contribution."
-
-      "Contributor" shall mean Licensor and any individual or Legal Entity
-      on behalf of whom a Contribution has been received by Licensor and
-      subsequently incorporated within the Work.
-
-   2. Grant of Copyright License. Subject to the terms and conditions of
-      this License, each Contributor hereby grants to You a perpetual,
-      worldwide, non-exclusive, no-charge, royalty-free, irrevocable
-      copyright license to reproduce, prepare Derivative Works of,
-      publicly display, publicly perform, sublicense, and distribute the
-      Work and such Derivative Works in Source or Object form.
-
-   3. Grant of Patent License. Subject to the terms and conditions of
-      this License, each Contributor hereby grants to You a perpetual,
-      worldwide, non-exclusive, no-charge, royalty-free, irrevocable
-      (except as stated in this section) patent license to make, have made,
-      use, offer to sell, sell, import, and otherwise transfer the Work,
-      where such license applies only to those patent claims licensable
-      by such Contributor that are necessarily infringed by their
-      Contribution(s) alone or by combination of their Contribution(s)
-      with the Work to which such Contribution(s) was submitted. If You
-      institute patent litigation against any entity (including a
-      cross-claim or counterclaim in a lawsuit) alleging that the Work
-      or a Contribution incorporated within the Work constitutes direct
-      or contributory patent infringement, then any patent licenses
-      granted to You under this License for that Work shall terminate
-      as of the date such litigation is filed.
-
-   4. Redistribution. You may reproduce and distribute copies of the
-      Work or Derivative Works thereof in any medium, with or without
-      modifications, and in Source or Object form, provided that You
-      meet the following conditions:
-
-      (a) You must give any other recipients of the Work or
-          Derivative Works a copy of this License; and
-
-      (b) You must cause any modified files to carry prominent notices
-          stating that You changed the files; and
-
-      (c) You must retain, in the Source form of any Derivative Works
-          that You distribute, all copyright, patent, trademark, and
-          attribution notices from the Source form of the Work,
-          excluding those notices that do not pertain to any part of
-          the Derivative Works; and
-
-      (d) If the Work includes a "NOTICE" text file as part of its
-          distribution, then any Derivative Works that You distribute must
-          include a readable copy of the attribution notices contained
-          within such NOTICE file, excluding those notices that do not
-          pertain to any part of the Derivative Works, in at least one
-          of the following places: within a NOTICE text file distributed
-          as part of the Derivative Works; within the Source form or
-          documentation, if provided along with the Derivative Works; or,
-          within a display generated by the Derivative Works, if and
-          wherever such third-party notices normally appear. The contents
-          of the NOTICE file are for informational purposes only and
-          do not modify the License. You may add Your own attribution
-          notices within Derivative Works that You distribute, alongside
-          or as an addendum to the NOTICE text from the Work, provided
-          that such additional attribution notices cannot be construed
-          as modifying the License.
-
-      You may add Your own copyright statement to Your modifications and
-      may provide additional or different license terms and conditions
-      for use, reproduction, or distribution of Your modifications, or
-      for any such Derivative Works as a whole, provided Your use,
-      reproduction, and distribution of the Work otherwise complies with
-      the conditions stated in this License.
-
-   5. Submission of Contributions. Unless You explicitly state otherwise,
-      any Contribution intentionally submitted for inclusion in the Work
-      by You to the Licensor shall be under the terms and conditions of
-      this License, without any additional terms or conditions.
-      Notwithstanding the above, nothing herein shall supersede or modify
-      the terms of any separate license agreement you may have executed
-      with Licensor regarding such Contributions.
-
-   6. Trademarks. This License does not grant permission to use the trade
-      names, trademarks, service marks, or product names of the Licensor,
-      except as required for reasonable and customary use in describing the
-      origin of the Work and reproducing the content of the NOTICE file.
-
-   7. Disclaimer of Warranty. Unless required by applicable law or
-      agreed to in writing, Licensor provides the Work (and each
-      Contributor provides its Contributions) on an "AS IS" BASIS,
-      WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
-      implied, including, without limitation, any warranties or conditions
-      of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
-      PARTICULAR PURPOSE. You are solely responsible for determining the
-      appropriateness of using or redistributing the Work and assume any
-      risks associated with Your exercise of permissions under this License.
-
-   8. Limitation of Liability. In no event and under no legal theory,
-      whether in tort (including negligence), contract, or otherwise,
-      unless required by applicable law (such as deliberate and grossly
-      negligent acts) or agreed to in writing, shall any Contributor be
-      liable to You for damages, including any direct, indirect, special,
-      incidental, or consequential damages of any character arising as a
-      result of this License or out of the use or inability to use the
-      Work (including but not limited to damages for loss of goodwill,
-      work stoppage, computer failure or malfunction, or any and all
-      other commercial damages or losses), even if such Contributor
-      has been advised of the possibility of such damages.
-
-   9. Accepting Warranty or Additional Liability. While redistributing
-      the Work or Derivative Works thereof, You may choose to offer,
-      and charge a fee for, acceptance of support, warranty, indemnity,
-      or other liability obligations and/or rights consistent with this
-      License. However, in accepting such obligations, You may act only
-      on Your own behalf and on Your sole responsibility, not on behalf
-      of any other Contributor, and only if You agree to indemnify,
-      defend, and hold each Contributor harmless for any liability
-      incurred by, or claims asserted against, such Contributor by reason
-      of your accepting any such warranty or additional liability.
-
-   END OF TERMS AND CONDITIONS
-
-   APPENDIX: How to apply the Apache License to your work.
-
-      To apply the Apache License to your work, attach the following
-      boilerplate notice, with the fields enclosed by brackets "[]"
-      replaced with your own identifying information. (Don't include
-      the brackets!)  The text should be enclosed in the appropriate
-      comment syntax for the file format. We also recommend that a
-      file or class name and description of purpose be included on the
-      same "printed page" as the copyright notice for easier
-      identification within third-party archives.
-
-   Copyright [yyyy] [name of copyright owner]
-
-   Licensed under the Apache License, Version 2.0 (the "License");
-   you may not use this file except in compliance with the License.
-   You may obtain a copy of the License at
-
-       http://www.apache.org/licenses/LICENSE-2.0
-
-   Unless required by applicable law or agreed to in writing, software
-   distributed under the License is distributed on an "AS IS" BASIS,
-   WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
-   See the License for the specific language governing permissions and
-   limitations under the License.

+ 0 - 14
x-pack/plugin/security/lib/nimbus-jose-jwt-modified-part1/licenses/nimbus-jose-jwt-NOTICE.txt

@@ -1,14 +0,0 @@
-Nimbus JOSE + JWT
-
-Copyright 2012 - 2018, Connect2id Ltd.
-
-Licensed under the Apache License, Version 2.0 (the "License"); you may not use
-this file except in compliance with the License. You may obtain a copy of the
-License at
-
-   http://www.apache.org/licenses/LICENSE-2.0
-
-Unless required by applicable law or agreed to in writing, software distributed
-under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR
-CONDITIONS OF ANY KIND, either express or implied. See the License for the
-specific language governing permissions and limitations under the License.

+ 0 - 26
x-pack/plugin/security/lib/nimbus-jose-jwt-modified-part2/build.gradle

@@ -1,26 +0,0 @@
-/*
- * Copyright Elasticsearch B.V. and/or licensed to Elasticsearch B.V. under one
- * or more contributor license agreements. Licensed under the Elastic License
- * 2.0; you may not use this file except in compliance with the Elastic License
- * 2.0.
- */
-
-apply plugin: 'elasticsearch.build'
-apply plugin: 'com.gradleup.shadow'
-
-// See the build.gradle file in the parent directory for an explanation of this unusual build
-
-dependencies {
-  implementation project(path: xpackModule('security:lib:nimbus-jose-jwt-modified-part1'), configuration: 'shadow')
-}
-
-tasks.named('shadowJar').configure {
-  // Drop everything in the original namespace, as the classes we want to modify have already been moved to another package by part 1
-  exclude 'com/nimbusds/'
-}
-
-['jarHell', 'thirdPartyAudit', 'forbiddenApisMain', 'splitPackagesAudit', 'licenseHeaders'].each {
-  tasks.named(it).configure {
-    enabled = false
-  }
-}

+ 0 - 29
x-pack/plugin/security/lib/nimbus-jose-jwt-modified/build.gradle

@@ -1,29 +0,0 @@
-/*
- * Copyright Elasticsearch B.V. and/or licensed to Elasticsearch B.V. under one
- * or more contributor license agreements. Licensed under the Elastic License
- * 2.0; you may not use this file except in compliance with the Elastic License
- * 2.0.
- */
-
-apply plugin: 'elasticsearch.build'
-apply plugin: 'com.gradleup.shadow'
-
-// See the build.gradle file in the parent directory for an explanation of this unusual build
-
-dependencies {
-  implementation "com.nimbusds:nimbus-jose-jwt:10.0.2"
-  implementation project(path: xpackModule('security:lib:nimbus-jose-jwt-modified-part2'), configuration: 'shadow')
-}
-
-tasks.named('shadowJar').configure {
-  manifest {
-    // The original library uses this and it gets stripped by shadowJar
-    attributes 'Automatic-Module-Name': 'com.nimbusds.jose.jwt'
-  }
-}
-
-['jarHell', 'thirdPartyAudit', 'forbiddenApisMain', 'splitPackagesAudit', 'licenseHeaders'].each {
-  tasks.named(it).configure {
-    enabled = false
-  }
-}

+ 0 - 202
x-pack/plugin/security/lib/nimbus-jose-jwt-modified/licenses/nimbus-jose-jwt-LICENSE.txt

@@ -1,202 +0,0 @@
-
-                                 Apache License
-                           Version 2.0, January 2004
-                        http://www.apache.org/licenses/
-
-   TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
-
-   1. Definitions.
-
-      "License" shall mean the terms and conditions for use, reproduction,
-      and distribution as defined by Sections 1 through 9 of this document.
-
-      "Licensor" shall mean the copyright owner or entity authorized by
-      the copyright owner that is granting the License.
-
-      "Legal Entity" shall mean the union of the acting entity and all
-      other entities that control, are controlled by, or are under common
-      control with that entity. For the purposes of this definition,
-      "control" means (i) the power, direct or indirect, to cause the
-      direction or management of such entity, whether by contract or
-      otherwise, or (ii) ownership of fifty percent (50%) or more of the
-      outstanding shares, or (iii) beneficial ownership of such entity.
-
-      "You" (or "Your") shall mean an individual or Legal Entity
-      exercising permissions granted by this License.
-
-      "Source" form shall mean the preferred form for making modifications,
-      including but not limited to software source code, documentation
-      source, and configuration files.
-
-      "Object" form shall mean any form resulting from mechanical
-      transformation or translation of a Source form, including but
-      not limited to compiled object code, generated documentation,
-      and conversions to other media types.
-
-      "Work" shall mean the work of authorship, whether in Source or
-      Object form, made available under the License, as indicated by a
-      copyright notice that is included in or attached to the work
-      (an example is provided in the Appendix below).
-
-      "Derivative Works" shall mean any work, whether in Source or Object
-      form, that is based on (or derived from) the Work and for which the
-      editorial revisions, annotations, elaborations, or other modifications
-      represent, as a whole, an original work of authorship. For the purposes
-      of this License, Derivative Works shall not include works that remain
-      separable from, or merely link (or bind by name) to the interfaces of,
-      the Work and Derivative Works thereof.
-
-      "Contribution" shall mean any work of authorship, including
-      the original version of the Work and any modifications or additions
-      to that Work or Derivative Works thereof, that is intentionally
-      submitted to Licensor for inclusion in the Work by the copyright owner
-      or by an individual or Legal Entity authorized to submit on behalf of
-      the copyright owner. For the purposes of this definition, "submitted"
-      means any form of electronic, verbal, or written communication sent
-      to the Licensor or its representatives, including but not limited to
-      communication on electronic mailing lists, source code control systems,
-      and issue tracking systems that are managed by, or on behalf of, the
-      Licensor for the purpose of discussing and improving the Work, but
-      excluding communication that is conspicuously marked or otherwise
-      designated in writing by the copyright owner as "Not a Contribution."
-
-      "Contributor" shall mean Licensor and any individual or Legal Entity
-      on behalf of whom a Contribution has been received by Licensor and
-      subsequently incorporated within the Work.
-
-   2. Grant of Copyright License. Subject to the terms and conditions of
-      this License, each Contributor hereby grants to You a perpetual,
-      worldwide, non-exclusive, no-charge, royalty-free, irrevocable
-      copyright license to reproduce, prepare Derivative Works of,
-      publicly display, publicly perform, sublicense, and distribute the
-      Work and such Derivative Works in Source or Object form.
-
-   3. Grant of Patent License. Subject to the terms and conditions of
-      this License, each Contributor hereby grants to You a perpetual,
-      worldwide, non-exclusive, no-charge, royalty-free, irrevocable
-      (except as stated in this section) patent license to make, have made,
-      use, offer to sell, sell, import, and otherwise transfer the Work,
-      where such license applies only to those patent claims licensable
-      by such Contributor that are necessarily infringed by their
-      Contribution(s) alone or by combination of their Contribution(s)
-      with the Work to which such Contribution(s) was submitted. If You
-      institute patent litigation against any entity (including a
-      cross-claim or counterclaim in a lawsuit) alleging that the Work
-      or a Contribution incorporated within the Work constitutes direct
-      or contributory patent infringement, then any patent licenses
-      granted to You under this License for that Work shall terminate
-      as of the date such litigation is filed.
-
-   4. Redistribution. You may reproduce and distribute copies of the
-      Work or Derivative Works thereof in any medium, with or without
-      modifications, and in Source or Object form, provided that You
-      meet the following conditions:
-
-      (a) You must give any other recipients of the Work or
-          Derivative Works a copy of this License; and
-
-      (b) You must cause any modified files to carry prominent notices
-          stating that You changed the files; and
-
-      (c) You must retain, in the Source form of any Derivative Works
-          that You distribute, all copyright, patent, trademark, and
-          attribution notices from the Source form of the Work,
-          excluding those notices that do not pertain to any part of
-          the Derivative Works; and
-
-      (d) If the Work includes a "NOTICE" text file as part of its
-          distribution, then any Derivative Works that You distribute must
-          include a readable copy of the attribution notices contained
-          within such NOTICE file, excluding those notices that do not
-          pertain to any part of the Derivative Works, in at least one
-          of the following places: within a NOTICE text file distributed
-          as part of the Derivative Works; within the Source form or
-          documentation, if provided along with the Derivative Works; or,
-          within a display generated by the Derivative Works, if and
-          wherever such third-party notices normally appear. The contents
-          of the NOTICE file are for informational purposes only and
-          do not modify the License. You may add Your own attribution
-          notices within Derivative Works that You distribute, alongside
-          or as an addendum to the NOTICE text from the Work, provided
-          that such additional attribution notices cannot be construed
-          as modifying the License.
-
-      You may add Your own copyright statement to Your modifications and
-      may provide additional or different license terms and conditions
-      for use, reproduction, or distribution of Your modifications, or
-      for any such Derivative Works as a whole, provided Your use,
-      reproduction, and distribution of the Work otherwise complies with
-      the conditions stated in this License.
-
-   5. Submission of Contributions. Unless You explicitly state otherwise,
-      any Contribution intentionally submitted for inclusion in the Work
-      by You to the Licensor shall be under the terms and conditions of
-      this License, without any additional terms or conditions.
-      Notwithstanding the above, nothing herein shall supersede or modify
-      the terms of any separate license agreement you may have executed
-      with Licensor regarding such Contributions.
-
-   6. Trademarks. This License does not grant permission to use the trade
-      names, trademarks, service marks, or product names of the Licensor,
-      except as required for reasonable and customary use in describing the
-      origin of the Work and reproducing the content of the NOTICE file.
-
-   7. Disclaimer of Warranty. Unless required by applicable law or
-      agreed to in writing, Licensor provides the Work (and each
-      Contributor provides its Contributions) on an "AS IS" BASIS,
-      WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
-      implied, including, without limitation, any warranties or conditions
-      of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
-      PARTICULAR PURPOSE. You are solely responsible for determining the
-      appropriateness of using or redistributing the Work and assume any
-      risks associated with Your exercise of permissions under this License.
-
-   8. Limitation of Liability. In no event and under no legal theory,
-      whether in tort (including negligence), contract, or otherwise,
-      unless required by applicable law (such as deliberate and grossly
-      negligent acts) or agreed to in writing, shall any Contributor be
-      liable to You for damages, including any direct, indirect, special,
-      incidental, or consequential damages of any character arising as a
-      result of this License or out of the use or inability to use the
-      Work (including but not limited to damages for loss of goodwill,
-      work stoppage, computer failure or malfunction, or any and all
-      other commercial damages or losses), even if such Contributor
-      has been advised of the possibility of such damages.
-
-   9. Accepting Warranty or Additional Liability. While redistributing
-      the Work or Derivative Works thereof, You may choose to offer,
-      and charge a fee for, acceptance of support, warranty, indemnity,
-      or other liability obligations and/or rights consistent with this
-      License. However, in accepting such obligations, You may act only
-      on Your own behalf and on Your sole responsibility, not on behalf
-      of any other Contributor, and only if You agree to indemnify,
-      defend, and hold each Contributor harmless for any liability
-      incurred by, or claims asserted against, such Contributor by reason
-      of your accepting any such warranty or additional liability.
-
-   END OF TERMS AND CONDITIONS
-
-   APPENDIX: How to apply the Apache License to your work.
-
-      To apply the Apache License to your work, attach the following
-      boilerplate notice, with the fields enclosed by brackets "[]"
-      replaced with your own identifying information. (Don't include
-      the brackets!)  The text should be enclosed in the appropriate
-      comment syntax for the file format. We also recommend that a
-      file or class name and description of purpose be included on the
-      same "printed page" as the copyright notice for easier
-      identification within third-party archives.
-
-   Copyright [yyyy] [name of copyright owner]
-
-   Licensed under the Apache License, Version 2.0 (the "License");
-   you may not use this file except in compliance with the License.
-   You may obtain a copy of the License at
-
-       http://www.apache.org/licenses/LICENSE-2.0
-
-   Unless required by applicable law or agreed to in writing, software
-   distributed under the License is distributed on an "AS IS" BASIS,
-   WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
-   See the License for the specific language governing permissions and
-   limitations under the License.

+ 0 - 14
x-pack/plugin/security/lib/nimbus-jose-jwt-modified/licenses/nimbus-jose-jwt-NOTICE.txt

@@ -1,14 +0,0 @@
-Nimbus JOSE + JWT
-
-Copyright 2012 - 2018, Connect2id Ltd.
-
-Licensed under the Apache License, Version 2.0 (the "License"); you may not use
-this file except in compliance with the License. You may obtain a copy of the
-License at
-
-   http://www.apache.org/licenses/LICENSE-2.0
-
-Unless required by applicable law or agreed to in writing, software distributed
-under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR
-CONDITIONS OF ANY KIND, either express or implied. See the License for the
-specific language governing permissions and limitations under the License.

+ 0 - 219
x-pack/plugin/security/lib/nimbus-jose-jwt-modified/src/main/java/com/nimbusds/jose/util/JSONObjectUtils.java

@@ -1,219 +0,0 @@
-/*
- * Copyright Elasticsearch B.V. and/or licensed to Elasticsearch B.V. under one
- * or more contributor license agreements. Licensed under the Elastic License
- * 2.0; you may not use this file except in compliance with the Elastic License
- * 2.0.
- */
-
-package com.nimbusds.jose.util;
-
-import java.net.URI;
-import java.security.AccessController;
-import java.security.PrivilegedAction;
-import java.security.PrivilegedActionException;
-import java.security.PrivilegedExceptionAction;
-import java.text.ParseException;
-import java.util.Date;
-import java.util.List;
-import java.util.Map;
-
-/**
- * This class wraps {@link org.elasticsearch.nimbus.jose.util.JSONObjectUtils}, which is copied directly from the source
- * library, and delegates to that class as quickly as possible. This layer is only here to provide a point at which we
- * can insert {@link java.security.AccessController#doPrivileged(PrivilegedAction)} calls as necessary. We don't do
- * anything here other than ensure gson has the proper security manager permissions.
- */
-public class JSONObjectUtils {
-
-    public static Map<String, Object> parse(final String s) throws ParseException {
-        try {
-            return AccessController.doPrivileged(
-                (PrivilegedExceptionAction<Map<String, Object>>) () -> org.elasticsearch.nimbus.jose.util.JSONObjectUtils.parse(s)
-            );
-        } catch (PrivilegedActionException e) {
-            throw (ParseException) e.getException();
-        }
-    }
-
-    public static Map<String, Object> parse(final String s, final int sizeLimit) throws ParseException {
-        try {
-            return AccessController.doPrivileged(
-                (PrivilegedExceptionAction<Map<String, Object>>) () -> org.elasticsearch.nimbus.jose.util.JSONObjectUtils.parse(
-                    s,
-                    sizeLimit
-                )
-            );
-        } catch (PrivilegedActionException e) {
-            throw (ParseException) e.getException();
-        }
-    }
-
-    @Deprecated
-    public static Map<String, Object> parseJSONObject(final String s) throws ParseException {
-        try {
-            return AccessController.doPrivileged(
-                (PrivilegedExceptionAction<Map<String, Object>>) () -> org.elasticsearch.nimbus.jose.util.JSONObjectUtils.parseJSONObject(s)
-            );
-        } catch (PrivilegedActionException e) {
-            throw (ParseException) e.getException();
-        }
-    }
-
-    public static boolean getBoolean(final Map<String, Object> o, final String key) throws ParseException {
-        try {
-            return AccessController.doPrivileged(
-                (PrivilegedExceptionAction<Boolean>) () -> org.elasticsearch.nimbus.jose.util.JSONObjectUtils.getBoolean(o, key)
-            );
-        } catch (PrivilegedActionException e) {
-            throw (ParseException) e.getException();
-        }
-    }
-
-    public static int getInt(final Map<String, Object> o, final String key) throws ParseException {
-        try {
-            return AccessController.doPrivileged(
-                (PrivilegedExceptionAction<Integer>) () -> org.elasticsearch.nimbus.jose.util.JSONObjectUtils.getInt(o, key)
-            );
-        } catch (PrivilegedActionException e) {
-            throw (ParseException) e.getException();
-        }
-    }
-
-    public static long getLong(final Map<String, Object> o, final String key) throws ParseException {
-        try {
-            return AccessController.doPrivileged(
-                (PrivilegedExceptionAction<Long>) () -> org.elasticsearch.nimbus.jose.util.JSONObjectUtils.getLong(o, key)
-            );
-        } catch (PrivilegedActionException e) {
-            throw (ParseException) e.getException();
-        }
-    }
-
-    public static float getFloat(final Map<String, Object> o, final String key) throws ParseException {
-        try {
-            return AccessController.doPrivileged(
-                (PrivilegedExceptionAction<Float>) () -> org.elasticsearch.nimbus.jose.util.JSONObjectUtils.getFloat(o, key)
-            );
-        } catch (PrivilegedActionException e) {
-            throw (ParseException) e.getException();
-        }
-    }
-
-    public static double getDouble(final Map<String, Object> o, final String key) throws ParseException {
-        try {
-            return AccessController.doPrivileged(
-                (PrivilegedExceptionAction<Double>) () -> org.elasticsearch.nimbus.jose.util.JSONObjectUtils.getDouble(o, key)
-            );
-        } catch (PrivilegedActionException e) {
-            throw (ParseException) e.getException();
-        }
-    }
-
-    public static String getString(final Map<String, Object> o, final String key) throws ParseException {
-        try {
-            return AccessController.doPrivileged(
-                (PrivilegedExceptionAction<String>) () -> org.elasticsearch.nimbus.jose.util.JSONObjectUtils.getString(o, key)
-            );
-        } catch (PrivilegedActionException e) {
-            throw (ParseException) e.getException();
-        }
-    }
-
-    public static URI getURI(final Map<String, Object> o, final String key) throws ParseException {
-        try {
-            return AccessController.doPrivileged(
-                (PrivilegedExceptionAction<URI>) () -> org.elasticsearch.nimbus.jose.util.JSONObjectUtils.getURI(o, key)
-            );
-        } catch (PrivilegedActionException e) {
-            throw (ParseException) e.getException();
-        }
-    }
-
-    public static List<Object> getJSONArray(final Map<String, Object> o, final String key) throws ParseException {
-        try {
-            return AccessController.doPrivileged(
-                (PrivilegedExceptionAction<List<Object>>) () -> org.elasticsearch.nimbus.jose.util.JSONObjectUtils.getJSONArray(o, key)
-            );
-        } catch (PrivilegedActionException e) {
-            throw (ParseException) e.getException();
-        }
-    }
-
-    public static String[] getStringArray(final Map<String, Object> o, final String key) throws ParseException {
-        try {
-            return AccessController.doPrivileged(
-                (PrivilegedExceptionAction<String[]>) () -> org.elasticsearch.nimbus.jose.util.JSONObjectUtils.getStringArray(o, key)
-            );
-        } catch (PrivilegedActionException e) {
-            throw (ParseException) e.getException();
-        }
-    }
-
-    public static Map<String, Object>[] getJSONObjectArray(final Map<String, Object> o, final String key) throws ParseException {
-        try {
-            return AccessController.doPrivileged(
-                (PrivilegedExceptionAction<Map<String, Object>[]>) () -> org.elasticsearch.nimbus.jose.util.JSONObjectUtils
-                    .getJSONObjectArray(o, key)
-            );
-        } catch (PrivilegedActionException e) {
-            throw (ParseException) e.getException();
-        }
-    }
-
-    public static List<String> getStringList(final Map<String, Object> o, final String key) throws ParseException {
-        try {
-            return AccessController.doPrivileged(
-                (PrivilegedExceptionAction<List<String>>) () -> org.elasticsearch.nimbus.jose.util.JSONObjectUtils.getStringList(o, key)
-            );
-        } catch (PrivilegedActionException e) {
-            throw (ParseException) e.getException();
-        }
-    }
-
-    public static Map<String, Object> getJSONObject(final Map<String, Object> o, final String key) throws ParseException {
-        try {
-            return AccessController.doPrivileged(
-                (PrivilegedExceptionAction<Map<String, Object>>) () -> org.elasticsearch.nimbus.jose.util.JSONObjectUtils.getJSONObject(
-                    o,
-                    key
-                )
-            );
-        } catch (PrivilegedActionException e) {
-            throw (ParseException) e.getException();
-        }
-    }
-
-    public static Base64URL getBase64URL(final Map<String, Object> o, final String key) throws ParseException {
-        try {
-            return AccessController.doPrivileged(
-                (PrivilegedExceptionAction<Base64URL>) () -> org.elasticsearch.nimbus.jose.util.JSONObjectUtils.getBase64URL(o, key)
-            );
-        } catch (PrivilegedActionException e) {
-            throw (ParseException) e.getException();
-        }
-    }
-
-    public static Date getEpochSecondAsDate(final Map<String, Object> o, final String key) throws ParseException {
-        try {
-            return AccessController.doPrivileged(
-                (PrivilegedExceptionAction<Date>) () -> org.elasticsearch.nimbus.jose.util.JSONObjectUtils.getEpochSecondAsDate(o, key)
-            );
-        } catch (PrivilegedActionException e) {
-            throw (ParseException) e.getException();
-        }
-    }
-
-    public static String toJSONString(final Map<String, ?> o) {
-        return AccessController.doPrivileged(
-            (PrivilegedAction<String>) () -> org.elasticsearch.nimbus.jose.util.JSONObjectUtils.toJSONString(o)
-        );
-    }
-
-    public static Map<String, Object> newJSONObject() {
-        return AccessController.doPrivileged(
-            (PrivilegedAction<Map<String, Object>>) org.elasticsearch.nimbus.jose.util.JSONObjectUtils::newJSONObject
-        );
-    }
-
-    private JSONObjectUtils() {}
-}

+ 0 - 26
x-pack/plugin/security/lib/nimbus-jose-jwt-modified/src/main/java/com/nimbusds/jose/util/JSONStringUtils.java

@@ -1,26 +0,0 @@
-/*
- * Copyright Elasticsearch B.V. and/or licensed to Elasticsearch B.V. under one
- * or more contributor license agreements. Licensed under the Elastic License
- * 2.0; you may not use this file except in compliance with the Elastic License
- * 2.0.
- */
-
-package com.nimbusds.jose.util;
-
-import java.security.AccessController;
-import java.security.PrivilegedAction;
-
-/**
- * This class wraps {@link JSONStringUtils}, which is copied directly from the source library, and delegates to
- * that class as quickly as possible. This layer is only here to provide a point at which we can insert
- * {@link java.security.AccessController#doPrivileged(PrivilegedAction)} calls as necessary. We don't do anything here
- * other than ensure gson has the proper security manager permissions.
- */
-public class JSONStringUtils {
-
-    public static String toJSONString(final String string) {
-        return AccessController.doPrivileged((PrivilegedAction<String>) () -> JSONStringUtils.toJSONString(string));
-    }
-
-    private JSONStringUtils() {}
-}