Related to a vulnerability found when working on https://github.com/fleetdm/fleet/pull/43295 https://github.com/fleetdm/fleet/pull/43295#discussion_r3065433754 `golang-jwt/jwt/v5` library already mitigates this, however, we are using `v4` which does not include this check. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Enforced RSA-only validation for JWTs used in authentication; tokens signed with non-RSA algorithms are now rejected. * **Tests** * Added tests to verify that non-RSA and unsigned JWTs are rejected and produce the expected error. <!-- end of auto-generated comment: release notes by coderabbit.ai -->