Recent Releases of https://github.com/doorkeeper-gem/doorkeeper
https://github.com/doorkeeper-gem/doorkeeper - v5.9.9
- Fix:
AuthorizedApplicationsControllernow answers401 Unauthorizedinstead of running with anilresource owner, which listed and revoked every token that has no resource owner — the ones the client credentials flow issues. Affected host applications are those whoseresource_owner_authenticatoranswersnilwithout halting the request itself; the generated initializer's example redirects and is not affected. - Fix:
AuthorizationsController#destroynow validates the client and redirect URI before producing the deny response, and renders — never redirects — when validation fails. Previously the deny path performed no OAuth-layer validation at all, allowing an open redirect to an attacker-controlled origin with the OAuthstateattached. Also reject unregisteredresponse_typevalues on the authorization endpoint rather than resolving them through theconstantizefallback. - Fix: refuse redirect URIs with a script scheme (
javascript,vbscript,data) both when an application is registered and at authorization time, regardless offorbid_redirect_uri. Such a URI is never a legitimate redirection endpoint, and withresponse_mode=form_postit became the action of the auto-submitting form the authorization server renders on its own origin. Already stored records with such a URI are now refused withinvalid_redirect_uribefore the consent screen is shown. - [#1938] Fix: a request body ActionDispatch cannot parse (malformed JSON under a JSON content type, say) no longer raises
ActionDispatch::Http::Parameters::ParseErrorout ofDoorkeeper::OAuth::Token.from_requestanddoorkeeper_token. Since 5.9.7 the RFC 6750 §2 multi-method check read the body on every request, so such a request raised even when it carried a valid Bearer header. The body is now treated as carrying no token, the same way ActionDispatch's own#filtered_parameterstreats that error.
- Ruby
Published by nbulaj 9 days ago
https://github.com/doorkeeper-gem/doorkeeper - v6.0.0.rc2
Please make sure you read the Upgrade guides
and changelog below before the update since this version includes breaking changes.
- [#1951] Fix: the built gem no longer contains
vendor/bundle. The gemspec globed all ofvendor/, which swept in the bundle installed by the release workflow; 6.0.0.rc1 is a 44.4 MB download against 154 KB for 6.0.0.beta2. - Fix:
AuthorizedApplicationsControllernow answers401 Unauthorizedinstead of running with anilresource owner, which listed and revoked every token that has no resource owner — the ones the client credentials flow issues. Affected host applications are those whoseresource_owner_authenticatoranswersnilwithout halting the request itself; the generated initializer's example redirects and is not affected. - Fix:
AuthorizationsController#destroynow validates the client and redirect URI before producing the deny response, and renders — never redirects — when validation fails. Previously the deny path performed no OAuth-layer validation at all, allowing an open redirect to an attacker-controlled origin with the OAuthstateattached. Also reject unregisteredresponse_typevalues on the authorization endpoint rather than resolving them through theconstantizefallback. - Fix: refuse redirect URIs with a script scheme (
javascript,vbscript,data) both when an application is registered and at authorization time, regardless offorbid_redirect_uri. Such a URI is never a legitimate redirection endpoint, and withresponse_mode=form_postit became the action of the auto-submitting form the authorization server renders on its own origin. Already stored records with such a URI are now refused withinvalid_redirect_uribefore the consent screen is shown. - [#1932] Fix: keep the scope originally granted by the resource owner on refresh tokens (RFC 6749 §6), so a chain narrowed on one refresh can return to its granted scope. Tracked in a new
refresh_token_scopescolumn; existing installations opt in withrails generate doorkeeper:refresh_token_scopes. - [#1933] Warn at boot when the
implicitorpasswordgrant flow is enabled: both are deprecated by RFC 9700 (OAuth 2.0 Security BCP) and removed from OAuth 2.1, and may be removed in a future Doorkeeper release. - [#1915] Fix: fetching a client's
jwks_urinow falls back to the other addresses returned by DNS when the first one cannot be connected to. - [#1934] The refresh_token grant now consults
custom_access_token_expires_in(withDoorkeeper::OAuth::REFRESH_TOKENas the context grant type) for the TTL of the refreshed access token. A callable that returnsnilfor this grant, or no callable at all, keeps inheriting the TTL of the token being refreshed as before. A callable that returns a value unconditionally now applies to refreshes as well. - [#1935] Add opt-in
public_client_access_token_expires_inconfiguration option: a ceiling for the lifetime of access tokens issued to public (non-confidential) clients by any grant, refresh_token included, as OAuth 2.1 Section 2.4 requires the exposure of tokens issued to unauthenticated clients to be limited. Confidential clients are not affected. - [#1938] Fix: a request body ActionDispatch cannot parse (malformed JSON under a JSON content type, say) no longer raises
ActionDispatch::Http::Parameters::ParseErrorout ofDoorkeeper::OAuth::Token.from_requestanddoorkeeper_token. Since 5.9.7 the RFC 6750 §2 multi-method check read the body on every request, so such a request raised even when it carried a valid Bearer header. The body is now treated as carrying no token, the same way ActionDispatch's own#filtered_parameterstreats that error. - [#1950] Document
hash_token_secrets/hash_application_secretsfallback:as a migration-period setting that should be removed once every row is hashed, and warn at boot for as long as one is configured. While a:plainfallback is active the stored value is itself a valid credential, so those columns need protecting as carefully as plaintext ones. - [#1953] Fix:
public_client_access_token_expires_innow also holds underreuse_access_tokenand with String TTLs, and the refresh_token grant handscustom_access_token_expires_inandresource_indicator_validatorwhat every other grant does.
- Ruby
Published by nbulaj 9 days ago
https://github.com/doorkeeper-gem/doorkeeper - v5.9.7
- Refuse requests that transmit an access token by more than one method (RFC 6750 §2), instead of silently authorizing with the first configured
access_token_methodsentry that matched and discarding the other tokens. Such a request now fails closed as carrying no usable token (401invalid_token); no calling contract changes. The form-encoded body (§2.2) and the URI query (§2.3) count as two methods even though Rails and Rack merge them into a singleparamshash. The same token repeated across two methods is refused too — §2 forbids the second method, not a disagreement between the two — and a custom callable extractor inaccess_token_methodskeeps the historical first-wins behavior and is never invoked more than once. (The strictinvalid_request(400) answer §3.1 prescribes ships with Doorkeeper 6.0.) - [#1925] Internal: pin the development dependency on
jsonbelow 3.0. json 3 removed the positional options Hash fromJSON.parseand thequirks_modeoption fromJSON.generate, both of which Active Support still uses, so the suite could not run on any supported Rails version.
- Ruby
Published by nbulaj 23 days ago
https://github.com/doorkeeper-gem/doorkeeper - v6.0.0.rc1
Please make sure you read the Upgrade guides
and changelog below before the update since this version includes breaking changes.
- Require Ruby >= 3.2 in the gemspec, matching the CI matrix (3.2 / 3.3 / 3.4 / 4.0). Ruby 2.7, 3.0 and 3.1 have reached end-of-life.
- Fix: the
client_secret_basicstrategy now requires aclient_idsent in the request body to name the same client as theAuthorization: Basicheader — the RFC 7521 §4.2 agreement checkprivate_key_jwtalready applies to an assertion's issuer. A request presenting Basic credentials for one client and aclient_idfor another was authenticated as the Basic client, silently discarding the other identity. A bareclient_idis not a client authentication method of its own, so the RFC 6749 §2.3 multiple-methods check does not (and should not) count it. - [#1906] Internal: exempt
Doorkeeper::ConfigfromMetrics/ClassLengthwith a directive on the class itself instead of raising the cop's global ceiling, so adding a configuration option no longer trips the limit. - [#1907] Fix: a
resourceparameter no longer produces a 500 at the authorization endpoint whenresource_indicator_validatoris configured without thedoorkeeper:resource_indicatorsmigration. Such a request is now answered withserver_error, as the token endpoint already did, and the missing migration is warned about at boot. - [#1909] Add Rails 8.1 to CI test matrix.
- [#1910] Add opt-in
validate_client_before_resource_owner_authenticationconfiguration option: the authorization endpoint validatesclient_idandredirect_uribefore authenticating the resource owner, so users are not sent through login for a request that can only fail. - [#1916] Fix broken Coveralls coverage reporting.
- [#1918] The api_only controller specs no longer
loadthe real controller sources, which detached the coverage of every other example that ran them and made the reported coverage depend on the random example order. - [#1923] Fix: the fallback secret upgrade no longer writes the matched secret back over a value stored in the meantime, which could undo a concurrent
#renew_secretand leave the superseded secret valid. Active Record writes the upgrade conditionally on the column still holding the value that matched; other ORMs can implement the newwrite_upgraded_secrethook. The Active Record write is a singleupdate_allstatement, so model callbacks and validations no longer run on this upgrade (timestamps and optimistic locking are still maintained). - [#1925] Internal: pin the development dependency on
jsonbelow 3.0. json 3 removed the positional options Hash fromJSON.parseand thequirks_modeoption fromJSON.generate, both of which Active Support still uses, so the suite could not run on any released Rails version. - [#1926] [BREAKING] Fix:
private_key_jwtclient authentication no longer accepts an audience derived from the request'sHostheader, which let a client assertion minted for another authorization server be replayed here. A server that configures neitherissuernor Rails'default_url_options[:host]now has no acceptable audience and refuses every assertion, and is warned about it at boot. - [BREAKING] Refuse requests that transmit the access token by more than one method (RFC 6750 §2) with an
invalid_requesterror, instead of silently authorizing with the first method that yielded a token and discarding the rest. The form-encoded body (§2.2) and the URI query (§2.3) count as two methods even though Rails and Rack merge them into a singleparamshash, and the same token repeated across two methods is refused too — §2 forbids the second method, not a disagreement between the two.- Only the built-in extraction methods take part in the check; a custom callable in
access_token_methodskeeps the historical first-wins behavior and is never invoked more than once. Doorkeeper::OAuth::Token.from_request/.authenticateraiseDoorkeeper::Errors::MultipleAccessTokenMethods.Doorkeeper.authenticateand everydoorkeeper_tokenhelper (Rails, Grape, and Doorkeeper's own controllers) keep their token-or-nil contract, sodoorkeeper_authorize!renders the refusal through a newdoorkeeper_bad_request_render_options(error:)hook (head 400unless you override it).- Upgrade note: under
handle_auth_errors :raisethese requests raiseDoorkeeper::Errors::InvalidRequest, a sibling ofDoorkeeper::Errors::InvalidTokenrather than a subclass — an existingrescue Doorkeeper::Errors::InvalidTokendoes not cover it.
- Only the built-in extraction methods take part in the check; a custom callable in
- Ruby
Published by nbulaj 23 days ago
https://github.com/doorkeeper-gem/doorkeeper - v5.9.6
- Reject requests that present more than one client identity (e.g. an
Authorization: Basicheader for one client and aclient_idparameter naming another) with aninvalid_requesterror, instead of authenticating the first extracted identity and silently discarding the other one. Aclient_idsent alongside another authentication method keeps working when it identifies the same client (RFC 7521 §4.2). Like the RFC 6749 §2.3 check released in 5.9.5, this validation does not apply whenclient_credentialsis configured with a callable extractor, since the credentials the remaining extractors would return are never evaluated — theclient_credentialsoption documents that now.
- Ruby
Published by nbulaj about 2 months ago
https://github.com/doorkeeper-gem/doorkeeper - 6.0.0.beta2
Please make sure you read the Upgrade guides
and changelog below before the update since this version includes breaking changes.
- [#1865] Revoke the token issued for an authorization code when the code is exchanged more than once, per RFC 6749 §4.1.2 / §10.5. Active when the
oauth_access_grants.access_token_idcolumn exists: new installs get it from the generated migration, existing apps can add it withrails generate doorkeeper:grant_reuse_revocation. Closes [#1713]. - [#1871] [BREAKING]
redirect_uriis now compared to the registered redirect URIs with the simple string comparison required by RFC 6749 §3.1.2.3 (the RFC 8252 §7.3 loopback port exception is kept). Clients relying on the previous lenient matching must send the exact registered URI, closes [#1718]. - [#1874] Fix
force_pkcerequiring acode_challengefrom response types that never issue an authorization code (e.g.token, or an OIDC extension'sid_token/id_token token). PKCE (RFC 7636) protects the authorization code exchange, so for code-less response types there is no token-endpoint step where acode_verifiercould ever be checked — such requests were rejected over a parameter that cannot be validated.force_pkcenow only enforces the challenge for response types that issue a code (codeand code-carrying hybrid types such ascode id_token). - [#1876] Fix: reject a non-string
scopeparameter (e.g.scope[a]=b, which Rack parses into a Hash) withinvalid_request(RFC 6749 §3.3) instead of an unhandled 500.Scopes.from_stringnow raisesErrors::InvalidScopeParameterfor a non-string argument — turned intoinvalid_requestby the token endpoint'srescue_from, so every grant type is covered — and the authorization endpoint rejects it up front in pre-authorization validation. The crash was reachable unauthenticated, before client authentication. - [#1877] Fix: let the
noneclient authentication strategy match a request whoseAuthorizationheader carries a Bearer token. A bearer credential authorizes access to the endpoint itself (e.g. a bearer-protected introspection endpoint per RFC 7662 §2.1, or a revocation request) rather than authenticating the client, so it must not suppress the public-clientnonestrategy when the client identifies itself with a bodyclient_id. Any other non-blankAuthorizationvalue — Basic, or aBearerwith no token — is still treated as header-based client authentication and continues to bypassnone. The 6.0.0.beta1 workaround of dropping theAuthorizationheader from such a request is no longer needed. - [#1878] Fix: the loopback redirect URI exception (RFC 8252 §7.3) now varies by port only, not by userinfo. The port was cleared with
URI#port=, which on Ruby >= 4.0 also drops the userinfo, sohttp://attacker@127.0.0.1/cbmatched a registeredhttp://127.0.0.1/cb. The match is now made component-by-component. The destination host is always the loopback interface, so this was not a cross-origin open redirect, and non-loopback hosts were never affected. - [#1879] Fix: with
reuse_access_tokenenabled, replaying an authorization code no longer revokes an access token that another grant still shares. The single-use revocation added in [#1865] followed the grant'saccess_token_id, which a reused token shares across grants, so a replay could collaterally revoke a token another valid session still held. The revocation now skips a token referenced by another grant and only reaches one unique to the replayed code; a token unique to the code is still revoked as before. - [#1881] Fix:
Doorkeeper::ApplicationsControllerno longer 500s oncreate/update/destroyinapi_onlymode, whereActionController::APIprovides noflash. Confiningflashto the HTML path is not sufficient on its own, because a client that does not name JSON explicitly still negotiates its way into that path — an absentAcceptheader and a browser-like list such asapplication/json, text/plain, */*both resolve totext/html, and a bare*/*resolves to the first registered format — soapi_onlymode now pins the response format to JSON. - [#1883] Internal: merge
CHANGELOG.mdwith git'suniondriver, so two pull requests that each add an entry no longer conflict on the line above "Please add here". - [#1884] Fix:
/oauth/introspectand/oauth/revokeextend the token lookup across both token types when the lookup bytoken_type_hintfinds nothing (RFC 7662 §2.1 / RFC 7009 §2.1), so a wrong hint no longer hides a token the server knows about ([#1882]) - [#1885] Index
oauth_access_grants.access_token_idin the migration templates: since [#1879] the code-replay revocation filters access grants by that column, the "never used to filter queries" premise behindindex: falseno longer holds. - [#1886] Add support for Resource Indicators for OAuth 2.0 (RFC 8707). Clients can include a
resourceparameter in authorization and token requests to indicate the target protected resource(s). The authorization server validates resource URIs, enforces audience restriction on tokens, and includesaudin introspection responses. Enable by configuringresource_indicator_validatorwith a callable. Requires newresourcecolumns on access grants and tokens — runrails generate doorkeeper:resource_indicatorsto add the migration. - [#1887] [test] Pin that a requested non-default scope reaches the authorization grant and the exchanged token, and that the authorization strategy shares the controller's pre-authorization — the mismatch reported in [#1576] does not reproduce. Test-only change, closes [#1576].
- [#1888] Document custom grant flow registration (
Doorkeeper::GrantFlow.register) in the README with a SAML 2.0 bearer assertion (RFC 7522) walkthrough, and pin URN-shaped custom grant types with an end-to-end request spec. Docs/test-only change, closes [#764]. - [#1890] [test] Pin that the authorization endpoint answers
invalid_redirect_urifor a client registered without a redirect URI (allow_blank_redirect_uri), whether or not the request supplies one — the behavior required by RFC 6749 §3.1.2.3. Test-only change, closes [#1682]. - [#1898] Fix: with
reuse_access_tokenenabled, theclient_credentialsgrant no longer reuses a token whoseresourcediffers from the one requested (RFC 8707), so the audience restriction the client asked for is always applied. Follow-up to [#1886]. - [#1899] Document the client authentication methods registry (
Doorkeeper::ClientAuthentication.register) in the README with a walkthrough for registering a custom method, and pin it with an end-to-end request spec. Docs/test-only change, closes [#1894]. - [#1891] Fix: an authorization request carrying a
redirect_urifor a client registered without one (redirect_uriisnilunderallow_blank_redirect_uri) now answersinvalid_redirect_uriinstead of crashing with an unhandled 500. - [#1896] Add an opt-in
private_key_jwtclient authentication method (RFC 7523 / OIDC Core §9, requires thejwtgem >= 2.7) that verifies assertions against the client's published public keys —jwks/jwks_uriattributes you define on your Application model, the latter fetched with an SSRF-hardened HTTP client. The jti replay guard and the fetched-JWKS cache are process-local by default and can be replaced with shared stores via theprivate_key_jwt_replay_guard/private_key_jwt_jwks_cacheconfig options. Part of [#1875]. - [#1901] [test] Pin the answered behaviors behind [#984], [#1554], [#1600], [#1663], [#1759] and [#1787] with regression specs — the built-in client authentication methods, the unmodified echo of long
statevalues, DB persistence with custom token generators, refresh token rotation/expiry semantics and the introspection asymmetry. Test-only change, closes those issues along with [#1291], [#1756] and [#1764]. - [#1902] Fix: requests that omit
scopenow compute the same default scopes at the authorization and token endpoints (Scopes#common, symmetric). With dynamic scopes enabled, a scope pattern in eitherdefault_scopesor the application's scopes grants the matching concrete scope at both endpoints, closes [#1889]. - [#1903] Fix:
revoke_previous_client_credentials_tokenno longer revokes a client's live access token issued for a differentresource([#1886]), so a client can keep one audience-restricted token per resource server. - [#1905] [test] Cover
private_key_jwtclient authentication on theclient_credentialsgrant, the one flow where an assertion is the client's only credential end to end. Test-only change.
- Ruby
Published by nbulaj about 2 months ago
https://github.com/doorkeeper-gem/doorkeeper - v5.9.5
- [#1901] Reject requests that authenticate the client with more than one method (RFC 6749 §2.3) with an
invalid_requesterror, instead of silently authenticating with the first method that matched and discarding the other credentials. - [#1853] Fix
reuse_access_tokenreusing a token that was created withcustom_access_token_attributesvalues when the new request doesn't specify any custom attributes. Such requests now only match tokens without custom attributes.
- Ruby
Published by nbulaj about 2 months ago
https://github.com/doorkeeper-gem/doorkeeper - v6.0.0.beta1
Please make sure you read the Upgrade guides and changelog below before the update since this version includes breaking changes.
- [#1816] Fix: redirect
unauthorized_clienterrors per RFC 6749 Section 4.1.2.1; validate redirect_uri beforeclient_supports_grant_flowto prevent open redirect - [#1867] Fix: use
access_deniedinstead ofinvalid_clientforresource_owner_authorize_for_clientvalidation per RFC 6749 Section 4.1.2.1.invalid_clientis a token endpoint error (Section 5.2), not an authorization endpoint error. - [#1838] Add OAuth 2.0 Authorization Server Metadata endpoint (RFC 8414) served at
/.well-known/oauth-authorization-server. The response is built from your Doorkeeper configuration and advertises the authorization, token, revocation and (when token introspection is enabled) introspection endpoints, supported scopes, response/grant types and PKCE code challenge methods. Two new config options are available:issuer(defaults to the request base URL) andcustom_metadata(a Hash merged into the response, e.g. to advertise an OIDCuserinfo_endpoint). The controller/response use the RFC 8414 "Metadata" naming so they don't collide with a future OpenID Connect Discovery (.well-known/openid-configuration) implementation. Endpoints disabled throughskip_controllersare omitted from the response instead of raising a route-generation error. - [#1839] Send client credentials in the request body (not the query string) in the token endpoint specs, per RFC 6749 §2.3.1. Test-only change: the
*_endpoint_urlhelpers now return a path plus a matching*_endpoint_paramsbuilder so flow specs post credentials through the body. - [#1840] Introduce a pluggable client authentication registry (RFC 6749 §2.3).
- New
client_authenticationconfig option declares which methods are accepted and in which order. Built-in strategies:client_secret_basic,client_secret_postandnone. - Custom strategies can be registered with
Doorkeeper::ClientAuthentication.register. - [BREAKING] Client credentials are no longer read from the query string — send them in the request body or via HTTP Basic. This applies to every endpoint that authenticates clients: token, revocation and introspection.
- [BREAKING] The
nonestrategy rejects requests that carry a non-blankAuthorizationheader. A common casualty is a public client POSTing to/oauth/revokewith a bodyclient_idwhile still sending itsAuthorization: Bearer <token>header — drop the header from that request. - [BREAKING] The
Doorkeeper::OAuth::Client::Credentialsclass methods.from_request,.from_basicand.from_paramsare removed — extensions extracting credentials from a request should register a client authentication method instead. - Deprecated: the
client_credentialsoption — useclient_authenticationinstead. - Deprecated: the
Doorkeeper::OAuth::Client::Credentialsconstant itself — it remains as an alias ofDoorkeeper::ClientAuthentication::Credentials(the plain uid/secret struct). - See the Upgrade Guide for detailed breaking changes, deprecations and migration steps.
- New
- [#1841] Reject requests that use more than one client authentication method (RFC 6749 §2.3: "The client MUST NOT use more than one authentication method in each request") with an
invalid_requesterror instead of silently using the first match. The request payload is validated against every registered method before the configured one is selected, so a client sending e.g. both Basic and body credentials is rejected even when only one of those methods is enabled. This applies to every endpoint that authenticates clients — token, revocation and introspection. Only real authentication mechanisms count: a bareclient_id(thenonemethod) is not a mechanism of its own, and deprecatedclient_credentialscallable extractors never count towards the limit (they keep the historical first-extractor-wins selection). - [#1842] [BREAKING]
force_pkcenow requires PKCE for all clients, including confidential ones, in line with the OAuth 2.0 Security BCP (RFC 9700) and OAuth 2.1. Previously confidential clients were exempt. If you enableforce_pkceand have confidential clients that do not yet send acode_challenge/code_verifier, their authorization requests will start to be rejected. - [#1845] Fix
NameErrorwhen the config option DSL (Doorkeeper::Config::Option) is extended into a class that does not defineself.builder_class. The guard raisedDoorkeeper::MissingConfigurationBuilderClass, a constant that was never defined, so callers sawuninitialized constantinstead of the intended message. The error is now defined asDoorkeeper::Errors::MissingConfigurationBuilderClass(aDoorkeeperError) and referenced correctly. - [#1846] Document and pin with regression specs that a
scopeparameter sent to the token endpoint is ignored for theauthorization_codegrant (RFC 6749 §4.1.3 does not define one): the access token always inherits the scopes of the authorization grant, and the response reports the actual grantedscope. No behavior change. - [#1847] Fix
Doorkeeper.config.enabled_grant_flows(andcalculate_grant_flows) not listing therefresh_tokengrant flow whenuse_refresh_tokenis configured, so consumers (e.g. RFC 8414 metadata) no longer need to append it manually — the built-in metadata endpoint now relies on this too. The flow is no longer duplicated intoken_grant_flowswhenrefresh_tokenis also listed ingrant_flowsexplicitly, a configuration-time warning is logged whengrant_flowsenablesrefresh_tokenwithoutuse_refresh_token(no refresh tokens would ever be issued), and the initializer template documents the flow. - [#1848] Derive
token_endpoint_auth_methods_supportedin the RFC 8414 metadata response from the effective client authentication configuration (including a deprecatedclient_credentials-only setup) instead of hardcoding the default methods. Servers that customizeclient_authentication(including extension-registered methods likeprivate_key_jwt) now see their metadata reflect what the server actually accepts; unregistered names are not advertised. - [#1849] Support RFC 9207 (Authorization Server Issuer Identification): when
issueris configured, theissparameter is added to the authorization responses redirected back to the client (successful and error responses alike) andauthorization_response_iss_parameter_supportedis advertised in the server metadata. Clients that parse the authorization redirect will start seeing the newissparameter. A configuredissuerthat is not RFC-compliant (not an https URL, or containing a query/fragment) now logs a warning at boot, as does a path-bearing issuer, which RFC 8414 clients would not discover through Doorkeeper's root-only well-known metadata route. - [#1850] Fix
reuse_access_tokenreturning a refresh token that doesn't match the request: token reuse now requires the candidate's refresh token presence to match what the request asks for, in both directions. A request that expects a refresh token (e.g.use_refresh_tokenenabled) no longer reuses a token issued without one (previously the refresh token was silently omitted), and a request that does not expect one no longer reuses a token that carries one (previously an unrequested refresh token was returned, reachable via a per-requestrefresh_token_enabledcallable). The requirement participates in the token matching itself, so an older matching token that satisfies it is still reused; a fresh token is created only when none does. API change for ORM extensions:matching_token_forandfind_matching_tokennow take an optional block (&filter) that a token must satisfy to count as a match — extensions overriding either method must accept the block and honor it (accept and yield). - [#1851] Fix duplicate query parameter in the authorization callback when a client's registered
redirect_urialready contains a parameter with the same name as a response parameter (e.g.state). The redirect query was merged with string keys on one side and symbol keys on the other, so a collision emitted the parameter twice (?state=fixed&code=...&state=user); the response parameter now overrides the registered one and appears exactly once. A blank response parameter (e.g. nostatesent with the request) leaves the registered parameter untouched, per RFC 6749 §3.1.2. - [#1852] Fix the
pkce_code_challenge_methodsconfig validator using line anchors (^/$) instead of string anchors (\A/\z), so a multi-line value such as"plain\ngarbage"passed validation and was retained as a (never-matching) challenge method instead of being rejected and reset to the default. - [#1853] Fix
reuse_access_tokenreusing a token that was created withcustom_access_token_attributesvalues when the new request doesn't specify any custom attributes. Such requests now only match tokens without custom attributes. - [#1854] Fix the RFC 8414 metadata endpoint raising
ActionController::UrlGenerationError(HTTP 500) whenuse_doorkeeperconfigures a custom controller whose namespace depth differs fromdoorkeeper/metadata(e.g.controllers tokens: "custom_tokens"). - [#1855] Perform the fallback secret upgrade-on-access write (plain → hashed token or application secret) through the primary database role, so
enable_multiple_database_rolessetups no longer attempt the write on a read replica when the lookup happens in a request routed to the reading role. - [#1857] Pin with regression specs that a
+between scopes in a form-encoded token request is decoded as a space (soscope=public+writerefreshes fine), while a percent-encoded literal+(%2B) names a single scope and is rejected when unknown, per RFC 6749 §3.3. Test-only change, closes [#1686]. - [#1859] Pin with regression specs that a refresh token bound to an expired access token can be revoked (fixed by [#1744]) and that the revoked refresh token is rejected at the token endpoint afterwards. Test-only change, closes [#1671].
- [#1860] Fix introspection of refresh tokens (RFC 7662): a refresh token bound to an expired access token now introspects as
active: true, matching the token endpoint which still accepts it. The introspection response for a presented refresh token no longer includes the paired access token'stoken_typeandexp. Fixes [#1858]. - [#1862] Document that with
reuse_access_tokenenabled token matching considers only the application, resource owner, scopes and custom token attributes — separate authorization grants for the same combination intentionally share one access token — and pin the behavior with a regression spec. Docs/test-only change, closes [#1693]. - [#1864] Fix
custom_access_token_attributesvalues being dropped when the authorization goes through the consent screen: the approve/deny forms now carry the custom attributes as hidden fields, and the pre-authorization JSON (api_onlymode) includes them so custom consent UIs can send them back. - [#1869] Improve test coverage
- [#1870] Fix: raise the intended
Doorkeeper::Errors::TokenGeneratorNotFound/UnableToGenerateToken(instead of a confusingNameError) whenapplication_secret_generatoris misconfigured.
- Ruby
Published by nbulaj 2 months ago
https://github.com/doorkeeper-gem/doorkeeper - v5.9.3
- [#1834] Fix default
allow_token_introspectionreturningfalsewhen a customapplication_classis configured. The default proc compared application objects with==, which fails when the authorized client and the introspected token's application are resolved as different classes (e.g. a baseDoorkeeper::Applicationvs. a configured subclass) even though they reference the same record. It now compares application ids instead. - [#1832] Fix confusing
belongs_to :ownerside effect:Doorkeeper::Models::Ownershipis now included only whenenable_application_owner?is set (read at include time), so models no longer expose a misleadingownerassociation/reflection when the application owner feature is disabled and the schema lacks the owner columns.
- Ruby
Published by nbulaj 4 months ago
https://github.com/doorkeeper-gem/doorkeeper - v5.9.2
- [#1822][#1823][#1825] Update Rubocop config, auto-corrections and codebase cleanup.
- [#1830] Fix
NameError: uninitialized constant ApplicationRecordonrails db:seed(and other non-eager-loading flows) caused byon_load(:active_record)firing re-entrantly duringApplicationRecordautoload. The orm hooks no longer depend onActiveSupport.on_load(:active_record); model concerns (Ownership,PolymorphicResourceOwner::ForAccessGrant,PolymorphicResourceOwner::ForAccessToken) are now wired up from eachMixins::*includedblock, which fires at parent-class autoload time — afterDoorkeeper.configurehas applied user settings and without re-entering the AR load chain.- Upgrade note: fully custom model classes that don't include
Doorkeeper::Orm::ActiveRecord::Mixins::{Application,AccessToken,AccessGrant}will no longer auto-receiveOwnership/PolymorphicResourceOwnerconcerns (previously injected byrun_orm_hooksvia the configured class name). Either inherit from the Doorkeeper default model, include the correspondingMixins::*module, orincludethe concerns directly.
- Upgrade note: fully custom model classes that don't include
- Ruby
Published by nbulaj 4 months ago
https://github.com/doorkeeper-gem/doorkeeper - v5.9.1
-
[#1781] Honor
handle_auth_errors :raiseinAuthorizationsController#authorize_response -
[#1795] Fix: detailed error 'insufficient_scope' in protected resources 403s
-
[#1797] Fix
doorkeeper:db:cleanuprake task failure on PostgreSQL -
[#1800] Set
@grant_typeinClientCredentialsRequestandRefreshTokenRequestconstructors sorequest.grant_typereturns
the correct value in hooks likebefore_successful_strategy_response. -
[#1802] Fix
filter_parametersnot applied whenDoorkeeper.configureis called inside to_prepare. -
[#1804] Use
ActiveSupport.on_load(:active_record)in ORM hooks to prevent loading ActiveRecord models too early -
[#1806] Fix token revocation bypass for public clients (RFC 7009)
-
[#1815] Expose
current_resource_owneras a view helper inDoorkeeper::ApplicationController. -
[#1818] Fix token introspection returning
exp: 0for non-expiring tokens. -
[#1784] Remove hardcoded colons from view templates, move punctuation to i18n translation strings.
[IMPORTANT]: if you have customized Doorkeeper views (
authorizations/new,authorizations/show,
applications/show) or overridden the defaulten.ymltranslations, you may need to update them.
Colons are no longer hardcoded in the views — they are now part of the translation strings.
Update the doorkeeper-i18n gem to get the
updated translations for all locales. -
[#1820] Remove dead wildcard presence check in
Scopes#dynamic_scope_match?(internal cleanup, no behavior change). -
[#1822] Update Rubocop config, auto-corrections.
-
[#1823] Update Rubocop config, part 2.
-
[#1825] Update Rubocop config, part 3.
-
[#1821] Fix noisy
Could not find command "no_previous_refresh_token_column?"Thor output during the
PreviousRefreshTokenGeneratorspec by stubbing the underlying DB column check instead of the generator's
private method (test-only change).
- Ruby
Published by nbulaj 5 months ago
https://github.com/doorkeeper-gem/doorkeeper - v.5.9.0
- [#1791] Add support for Rails read replicas with automatic role switching via
enable_multiple_database_rolesconfiguration option - [#1792] Consider expires_in when clear expired tokens with StaleRecordsCleaner.
- [#1790] Fix race condition in refresh token revocation check by moving InvalidGrantReuse check inside the lock block
- [#1788] Fix regex for basic auth to be case-insensitive
- [#1775] Fix Applications Secret Not Null Constraint generator
- [#1779] Only lock previous access token model when creating a new token from its refresh token if revoke_previous_refresh_token_on_use is false
- [#1778] Ensure that token revocation is idempotent by checking that that token has not already been revoked before revoking.
- Ruby
Published by nbulaj 7 months ago
https://github.com/doorkeeper-gem/doorkeeper -
- [#1755] Fix the error message for force_pkce
- [#1761] Memoize authentication failure
- [#1762] Allow missing client to trigger invalid client error when force_pkce is enabled
- [#1767] Make sure error handling happens on a controller level opposed to action level to account for the controller being extended
- Ruby
Published by nbulaj over 1 year ago
https://github.com/doorkeeper-gem/doorkeeper - v5.8.1
- [#1752] Bump the range of supported Ruby and Rails versions
- [#1747] Fix unknown pkce method error when configured
- [#1744] Allow for expired refresh tokens to be revoked
- [#1754] Fix refresh tokens with dynamic scopes
- Ruby
Published by nbulaj almost 2 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.8.0
- [#1739] Add support for dynamic scopes
- [#1715] Fix token introspection invalid request reason
- [#1714] Fix
Doorkeeper::AccessToken.find_or_create_forwith empty scopes which raises NoMethodError - [#1712] Add
Pragma: no-cacheto token response - [#1726] Refactor token introspection class.
- [#1727] Allow to set null secret value for Applications if they are public.
- [#1735] Add
pkce_code_challenge_methodsconfig option.
- Ruby
Published by nbulaj almost 2 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.7.1
- [#1705] Add
force_pkceoption that requires non-confidential clients to use PKCE when requesting an access_token using an authorization code
- Ruby
Published by nbulaj over 2 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.7.0
- [#1696] Add missing #issued_token method to OAuth::TokenResponse
- [#1697] Allow a TokenResponse body to be customized (memoize response body).
- [#1702] Fix bugs for error response in the form_post and error view
- [#1660] Custom access token attributes are now considered when finding matching tokens (fixes #1665). Introduce revoke_previous_client_credentials_token configuration option.
- Ruby
Published by nbulaj over 2 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.6.9
- [#1691] Make new Doorkeeper errors backward compatible with older extensions.
- Ruby
Published by nbulaj over 2 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.6.8
- [#1680] Fix handle_auth_errors :raise NotImplementedError
- Ruby
Published by nbulaj almost 3 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.6.7
- [#1662] Specify uri_redirect validation class explicitly.
- [#1652] Add custom attributes support to token generator.
- [#1667] Pass
clientinstead ofgrant.applicationtofind_or_create_access_token. - [#1673] Honor
custom_access_token_attributesin client credentials grant flow. - [#1676] Improve AuthorizationsController error response handling
- [#1677] Fix URIHelper.valid_for_authorization? breaking for non url URIs.
- Ruby
Published by nbulaj almost 3 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.6.6
- [#1644] Update HTTP headers.
- [#1646] Block public clients automatic authorization skip.
- [#1648] Add custom token attributes to Refresh Token Request.
- [#1649] Fixed custom_access_token_attributes related errors.
- Ruby
Published by nbulaj over 3 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.6.5
- [#1602] Allow custom data to be stored inside access grants/tokens.
- [#1634] Code refactoring for custom token attributes.
- [#1639] Add grant type validation to avoid Internal Server Error for DELETE /oauth/authorize endpoint.
- Ruby
Published by nbulaj over 3 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.6.4
- [#1633] Apply ORM configuration in #to_prepare block to avoid autoloading errors.
- Ruby
Published by nbulaj over 3 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.6.3
- [#1622] Drop support for Rubies 2.5 and 2.6
- [#1605] Fix URI validation for Ruby 3.2+.
- [#1625] Exclude endless access tokens from
StaleRecordsCleaner. - [#1626] Remove deprecated
active_record_optionsconfig option. - [#1631] Fix regression with redirect behavior after token lookup optimizations (redirect to app URI when found).
- [#1630] Special case unique index creation for refresh_token on SQL Server.
- [#1627] Lazy evaluate Doorkeeper config when loading files and executing initializers.
- Ruby
Published by nbulaj over 3 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.6.2
- [#1604] Fix fetching of the application when custom application_class defined.
- Ruby
Published by nbulaj almost 4 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.6.1
- [#1593] Add support for Trilogy ActiveRecord adapter.
- [#1597] Add optional support to use the url path for the native authorization code flow. Ports forward [#1143] from 4.4.3
- [#1599] Remove unnecessarily re-fetch of application object when creating an access token.
- Ruby
Published by nbulaj almost 4 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.6.0
- [#1581] Consider
token_type_hintwhen searching for access token in TokensController to avoid extra database calls.
- Ruby
Published by nbulaj about 4 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.6.0.rc1
-
[#1551] Change lazy loading for ORM to be Ruby standard autoload.
-
[#1552] Remove duplicate IDs on Auth form to improve accessibility.
-
[#1542] Improve performance of
Doorkeeper::AccessToken#matching_token_forusing database specific SQL time math.[IMPORTANT]: API of the
Doorkeeper::AccessToken#matching_token_formethod has changed and now it returns
only active access tokens (previously they were just not revoked). Please remember that the idea of the
reuse_access_tokenoption is to check for existing active token (see configuration option description).
- Ruby
Published by nbulaj over 4 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.5.4
- [#1535] Revert changes introduced in #1528 to allow query params in
redirect_urias per the spec.
- Ruby
Published by nbulaj almost 5 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.5.3
- [#1528] Don't allow extra query params in redirect_uri.
- [#1525] I18n source for forbidden token error is now
doorkeeper.errors.messages.forbidden_token.missing_scope. - [#1531] Disable
strict-loadingfor Doorkeeper models by default. - [#1532] Add support for Rails 7.
- Ruby
Published by nbulaj about 5 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.5.2
- [#1502] Drop support for Ruby 2.4 because of EOL.
- [#1504] Updated the url fragment in the comment for code documentation.
- [#1512] Fix form behavior when response mode is form_post.
- [#1511] Fix that authorization code is returned by fragment if response_mode is fragament.
- Ruby
Published by nbulaj over 5 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.5.1
- [#1496] Revoke
old_refresh_tokenifprevious_refresh_tokenis present. - [#1495] Fix
respond_toundefined in API-only mode - [#1488] Verify client authentication for Resource Owner Password Grant when
config.skip_client_authentication_for_password_grantis set and the client credentials
are sent in a HTTP Basic auth header.
- Ruby
Published by nbulaj over 5 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.5.0
- [#1482] Simplify
TokenInfoControllerto be overridable (extract response rendering). - [#1478] Fix ownership association and Rake tasks when custom models configured.
- [#1477] Respect ActiveRecord::Base.pluralize_table_names for Doorkeeper table names.
- Ruby
Published by nbulaj over 5 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.5.0.rc2
-
[#1473] Enable
ApplicationsandAuthorizedApplicationscontrollers in API mode.[IMPORTANT] you can still skip these controllers using
skip_controllersin
use_doorkeeperinsideroutes.rb. Please do it in case you don't need them. -
[#1472] Fix
establish_connectionconfiguration for custom defined models. -
[#1471] Add support for Ruby 3.0.
-
[#1469] Check if
redirect_uriexists. -
[#1465] Memoize nil doorkeeper_token.
-
[#1459] Use built-in Ruby option to remove padding in PKCE code challenge value.
-
[#1457] Make owner_id a bigint for newly-generated owner migrations
-
[#1452] Empty previous_refresh_token only if present.
-
[#1440] Validate empty host in redirect_uri.
-
[#1438] Add form post response mode.
-
[#1458] Make
config.skip_client_authentication_for_password_granta long term configuration option.
- Ruby
Published by nbulaj over 5 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.5.0.rc1
-
[#1435] Make error response not redirectable when client is unauthorized
-
[#1426] Ensure ActiveRecord callbacks are executed on token revocation.
-
[#1407] Remove redundant and complex to support helpers froms tests (
should_have_json, etc). -
[#1416] Don't add introspection route if token introspection completely disabled.
-
[#1410] Properly memoize
current_resource_ownervalue (considernilandfalsevalues). -
[#1415] Ignore PKCE params for non-PKCE grants.
-
[#1418] Add ability to register custom OAuth Grant Flows.
-
[#1420] Require client authentication for Resource Owner Password Grant as stated in OAuth RFC.
[IMPORTANT] you need to create a new OAuth client (
Doorkeeper::Application) if yoo didn't
have it before and use client credentials in HTTP Basic auth if you previously used this grant
flow without client authentication. For migration purposes you could enable
skip_client_authentication_for_password_grantconfiguration option totrue, but such behavior
(as well as configuration option) would be completely removed in a future version of Doorkeeper.
All the users of your provider application now need to include client credentials when they use
this grant flow. -
[#1421] Add Resource Owner instance to authorization hook context for
custom_access_token_expires_in
configuration option to allow resource owner based Access Tokens TTL.
- Ruby
Published by nbulaj about 6 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.4.0
- [#1404] Make
Doorkeeper::Application#read_attribute_for_serializationpublic.
- Ruby
Published by nbulaj over 6 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.0.3
- [#1371] Backport: add #as_json method and attributes serialization restriction for Application model.
Fixes information disclosure vulnerability (CVE-2020-10187).
- Ruby
Published by nbulaj over 6 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.3.2
- [#1371] Backport: Add
#as_jsonmethod and attributes serialization restriction for Application model.
Fixes information disclosure vulnerability (CVE-2020-10187).
- Ruby
Published by nbulaj over 6 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.2.5
- [#1371] Backport: Add
#as_jsonmethod and attributes serialization restriction for Application model.
Fixes information disclosure vulnerability (CVE-2020-10187).
- Ruby
Published by nbulaj over 6 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.1.1
- [#1371] Backport: Add
#as_jsonmethod and attributes serialization restriction for Application model.
Fixes information disclosure vulnerability (CVE-2020-10187).
- Ruby
Published by nbulaj over 6 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.4.0.rc2
-
[#1371] Add
#as_jsonmethod and attributes serialization restriction for Application model.
Fixes information disclosure vulnerability (CVE-2020-10187).[IMPORTANT] you need to re-implement
#as_jsonmethod for Doorkeeper Application model
if you previously used#to_jsonserialization with custom options or attributes or rely on
JSON response from /oauth/applications.json or /oauth/authorized_applications.json. This change
is a breaking change which restricts serialized attributes to a very small set of columns. -
[#1395] Fix
NameError: uninitialized constant Doorkeeper::AccessTokenfor Rake tasks. -
[#1397] Add
as: :doorkeeper_applicationon Doorkeeper application form in order to support
custom configured application model. -
[#1400] Correctly yield the application instance to
allow_grant_flow_for_client?config
option (fixes #1398). -
[#1402] Handle trying authorization with client credentials.
- Ruby
Published by nbulaj over 6 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.4.0.rc1
-
[#1366] Sets expiry of token generated using
refresh_tokento that of original token. (Fixes #1364) -
[#1354] Add
authorize_resource_owner_for_clientoption to authorize the calling user to access an application. -
[#1355] Allow to enable polymorphic Resource Owner association for Access Token & Grant
models (use_polymorphic_resource_ownerconfiguration option).[IMPORTANT] Review your custom patches or extensions for Doorkeeper internals if you
have such - since now Doorkeeper passes Resource Owner instance to every objects and not
just it's ID. See PR description for details. -
[#1356] Remove duplicated scopes from Access Tokens and Grants on attribute assignment.
-
[#1357] Fix
Doorkeeper::OAuth::PreAuthorization#as_jsonmethod causing
Stack level too deeperror with AMS (fix #1312). -
[#1358] Deprecate
active_record_optionsconfiguration option. -
[#1359] Refactor Doorkeeper configuration options DSL to make it easy to reuse it
in external extensions. -
[#1360] Increase
matching_token_forlookup size to 10 000 and make it configurable. -
[#1371] Fix controllers to use valid classes in case Doorkeeper has custom models configured.
-
[#1370] Fix revocation response for invalid token and unauthorized requests to conform with RFC 7009 (fixes #1362).
[IMPORTANT] now fully according to RFC 7009 nobody can do a revocation request without
client_id
(for public clients) andclient_secret(for private clients). Please update your apps to include that
info in the revocation request payload. -
[#1373] Make Doorkeeper routes mapper reusable in extensions.
-
[#1374] Revoke and issue client credentials token in a transaction with a row lock.
-
[#1384] Add context object with auth/pre_auth and issued_token for authorization hooks.
-
[#1387] Add
AccessToken#create_forand use inRefreshTokenRequest. -
[#1392] Fix
enable_polymorphic_resource_ownermigration template to have proper index name. -
[#1393] Improve Applications #show page with more informative data on client secret and scopes.
-
[#1394] Use Ruby
autoloadfeature to load Doorkeeper files.
- Ruby
Published by nbulaj over 6 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.3.1
- [#1360] Backport: Increase
matching_token_forbatch lookup size to 10 000 and make it configurable.
- Ruby
Published by nbulaj over 6 years ago
https://github.com/doorkeeper-gem/doorkeeper -
- [#1360] Backport: Increase
matching_token_forbatch lookup size to 10 000 and make it configurable.
- Ruby
Published by nbulaj over 6 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.3.0
-
[#1339] Validate Resource Owner in
PasswordAccessTokenRequestagainstnilandfalsevalues. -
[#1341] Fix
refresh_token_revoked_on_usewithhash_token_secretsenabled. -
[#1343] Fix ruby 2.7 kwargs warning in InvalidTokenResponse.
-
[#1345] Allow to set custom classes for Doorkeeper models, extract reusable AR mixins.
-
[#1346] Refactor
Doorkeeper::Application#to_jsoninto convenient#as_json(fix #1344). -
[#1349] Fix
Doorkeeper::ApplicationAR associations using an incorrect foreign key name when using a custom class. -
[#1318] Make existing token revocation for client credentials optional and disable it by default.
[IMPORTANT] This is a change compared to the behaviour of version 5.2. If you were relying on access tokens being revoked once the same client requested a new access token, reenable it with
revoke_previous_client_credentials_tokenin Doorkeeper initialization file.
- Ruby
Published by nbulaj over 6 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.2.3
- [#1334] Remove
application_secretflash helper andredirect_tokeyword. - [#1331] Move redirect_uri_validator to where it is used (
Applicationmodel). - [#1326] Move response_type check in pre_authorization to a method to be easily to override.
- [#1329] Fix
find_in_batchesorder warning.
- Ruby
Published by nbulaj almost 7 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.2.2
- [#1320] Call configured
authenticate_resource_ownermethod once per request. - [#1315] Allow generation of new secret with
Doorkeeper::Application#renew_secret. - [#1309] Allow
Doorkeeper::Application#to_jsonto work without arguments.
- Ruby
Published by nbulaj almost 7 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.2.1
- [#1308] Fix flash types for
api_onlymode (no flashes forActionController::API). - [#1306] Fix interpolation of
missing_parami18n.
- Ruby
Published by nbulaj about 7 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.2.0
- [#1305] Make
Doorkeeper::ApplicationControllerto inherit fromActionController::APIin cases whenapi_modeenabled (fixes #1302).
- Ruby
Published by nbulaj about 7 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.2.0.rc3
- [#1298] Slice strong params so doesn't error with Rails forms.
- [#1300] Limiting access to attributes of pre_authorization.
- [#1296] Adding client_id to strong parameters.
- [#1293] Move ar specific redirect uri validator to ar orm directory.
- [#1288] Allow to pass attributes to the
Doorkeeper::OAuth::PreAuthorization#as_jsonmethod to customize
the PreAuthorization response. - [#1286] Add ability to customize grant flows per application (OAuth client) (#1245 , #1207)
- [#1283] Allow to customize base class for
Doorkeeper::ApplicationMetalController(new configuration
option calledbase_metal_controller(fix #1273). - [#1277] Prevent requested scope be empty on authorization request, handle and add description for invalid request.
- Ruby
Published by nbulaj about 7 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.2.0.rc2
- [#1270] Find matching tokens in batches for reuse_access_token option (fix #1193).
- [#1271] Reintroduce existing token revocation for client credentials.
- [#1269] Update initializer template documentation.
- [#1266] Use strong parameters within pre-authorization.
- [#1264] Add :before_successful_authorization and :after_successful_authorization hooks in TokensController
- [#1263] Response properly when introspection fails and fix configurations's user guide.
- Ruby
Published by nbulaj over 7 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.2.0.rc1
- [#1260], [#1262] Improve Token Introspection configuration option (access to tokens, client).
- [#1257] Add constraint configuration when using client authentication on introspection endpoint.
- [#1252] Returning
unauthorizedwhen the revocation of the token should not be performed due to wrong permissions. - [#1249] Specify case sensitive uniqueness to remove Rails 6 deprecation message
- [#1248] Display the Application Secret in HTML after creating a new application even when
hash_application_secretsis used. - [#1248] Return the unhashed Application Secret in the JSON response after creating new application even when
hash_application_secretsis used. - [#1238] Better support for native app with support for custom scheme and localhost redirection.
- Ruby
Published by nbulaj over 7 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.1.0
See Upgrade guides for migration to a new version.
- [#1243]: Add nil check operator in token checking at token introspection.
- [#1241] Explaining foreign key options for resource owner in a single place
- [#1237] Allow to set blank redirect URI if Doorkeeper configured to use redirect URI-less grant flows.
- [#1234] Fix
StaleRecordsCleanerto properly work with big amount of records. - [#1228] Allow to explicitly set non-expiring tokens in
custom_access_token_expires_inconfiguration
option usingFloat::INIFINITYreturn value. - [#1224] Do not try to store token if not found by fallback hashing strategy.
- [#1223] Update Hound/Rubocop rules, correct Doorkeeper codebase to follow style-guides.
- [#1220] Drop Rails 4.2 & Ruby < 2.4 support.
- Ruby
Published by nbulaj over 7 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.1.0.rc2
-
[#1208] Unify hashing implementation into secret storing strategies
[IMPORTANT]: If you have been using the master branch of doorkeeper with bcrypt in your Gemfile.lock,
your application secrets have been hashed using BCrypt. To restore this behavior, use the initializer option
use_application_hashing using: 'Doorkeeper::SecretStoring::BCrypt. -
[#1216] Add nil check to
expires_atmethod. -
[#1215] Fix deprecates for Rails 6.
-
[#1214] Scopes field accepts array.
-
[#1209] Fix tokens validation for Token Introspection request.
-
[#1202] Use correct HTTP status codes for error responses.
[IMPORTANT]: this change might break your application if you were relying on the previous
401 status codes, this is now a 400 by default, or a 401 forinvalid_clientandinvalid_tokenerrors. -
[#1201] Fix custom TTL block
clientparameter to always be anDoorkeeper::Applicationinstance.[IMPORTANT]: those who defined
custom_access_token_expires_inconfiguration option need to check
their block implementation: if you are usingoauth_client.applicationto getDoorkeeper::Application
instance, then you need to replace it with justoauth_client. -
[#1200] Increase default Doorkeeper access token value complexity (
urlsafe_base64instead of justhex)
matching RFC6749/RFC6750.[IMPORTANT]: this change have possible side-effects in case you have custom database constraints for
access token value, application secrets, refresh tokens or you patched Doorkeeper models and introduced
token value validations, or you are using database with case-insensitive WHERE clause like MySQL
(you can face some collisions). Before this change access token value matched[a-f0-9]regex, and now
it matches[a-zA-Z0-9\-_]. In case you have such restrictions and your don't use custom token generator
please change configuration optiondefault_generator_methodto:hex. -
[#1195] Allow to customize Token Introspection response (fixes #1194).
-
[#1189] Option to set
token_reuse_limit. -
[#1191] Try to load bcrypt for hashing of application secrets, but add fallback.
- Ruby
Published by nbulaj over 7 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.1.0.rc1
- [#1188] Use
paramsinstead ofrequest.POSTin tokens controller (fixes #1183). - [#1182] Fix loopback IP redirect URIs to conform with RFC8252, p. 7.3 (fixes #1170).
- [#1179] Authorization Code Grant Flow without client id returns invalid_client error.
- [#1177] Allow to limit
scopesfor certaingrant_types - [#1176] Fix test factory support for
factory_bot_rails - [#1175] Internal refactor: use
scopes_stringinsidescopes. - [#1168] Allow optional hashing of tokens and secrets.
- [#1164] Fix error when
root_pathis not defined. - [#1162] Fix
enforce_content_typefor requests without body.
- Ruby
Published by nbulaj over 7 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.0.2
- [#1158] Fix initializer template: change handle_auth_errors option
- [#1157] Remove redundant index from migration template.
- Ruby
Published by nbulaj almost 8 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.0.1
- [#1140] Allow rendering custom errors from exceptions (issue #844). Originally opened as [#944].
- [#1138] Revert regression bug (check for token expiration in Authorizations controller so authorization
triggers every time) - [#1149] Fix for
URIChecker#valid_for_authorization?false negative when query is blank, but?present. - [#1151] Fix Refresh Token strategy: add proper validation of client credentials both for Public & Private clients.
- [#1152] Fix migration template: change resource owner data type from integer to Rails generic
references - [#1154] Refactor
StaleRecordsCleanerto be ORM agnostic.
- Ruby
Published by nbulaj almost 8 years ago
https://github.com/doorkeeper-gem/doorkeeper - v4.4.3
- [#1143] Adds a config option opt_out_native_route_change to opt out of the breaking api changed introduced in https://github.com/doorkeeper-gem/doorkeeper/pull/1003
- Ruby
Published by nbulaj about 8 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.0.0
- [#1127] Change the token_type initials of the Banner Token to uppercase to comply with the RFC6750 specification.
- Ruby
Published by nbulaj about 8 years ago
https://github.com/doorkeeper-gem/doorkeeper - v4.4.2
- [#1130] Backport fix for native redirect_uri from 5.x.
- Ruby
Published by nbulaj about 8 years ago
https://github.com/doorkeeper-gem/doorkeeper - v4.4.1
- [#1127] Backport token type to comply with the RFC6750 specification.
- [#1125] Backport Quote surround I18n yes/no keys
- Ruby
Published by nbulaj about 8 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.0.0.rc2
- [#1106] Restrict access to AdminController with 'Forbidden 403' if admin_authenticator is not
configured by developers.. - [#1108] Simple formating of callback URLs when listing oauth applications
- [#1116]
AccessGrants will now be revoked along withAccessTokens when
hitting theAuthorizedApplicationController#destroyroute. - [#1114] Make token info endpoint's attributes consistent with token creation
- [#1119] Fix token revocation for OAuth apps using "implicit" grant flow
- [#1122] Fix AuthorizationsController#new error response to be in JSON format
- Ruby
Published by nbulaj about 8 years ago
https://github.com/doorkeeper-gem/doorkeeper - v4.4.0
- [#1120] Backport security fix from 5.x for token revocation when using public clients
- Ruby
Published by nbulaj about 8 years ago
https://github.com/doorkeeper-gem/doorkeeper - v5.0.0.rc1
- [#1103] Allow customizing use_refresh_token
- [#1089] Removed enable_pkce_without_secret configuration option
- [#1102] Expiration time based on scopes
- [#1099] All the configuration variables in
Doorkeeper.configurationnow
always return a non-nil value (trueorfalse) - [#1099] ORM / Query optimization: Do not revoke the refresh token if it is not enabled
indoorkeeper.rb - [#996] Expiration Time Base On Grant Type
- [#997] Allow PKCE authorization_code flow as specified in RFC7636
- [#907] Fix lookup for matching tokens in certain edge-cases
- [#992] Add API option to use Doorkeeper without management views for API only
Rails applications (api_only) - [#1045] Validate redirect_uri as the native URI when making authorization code requests
- [#1048] Remove deprecated
Doorkeeper#configured?,Doorkeeper#database_installed?, and
Doorkeeper#installed?method - [#1031] Allow public clients to authenticate without
client_secret. Define an app as
either public or private/confidential - [#1010] Add configuration to enforce configured scopes (
default_scopesand
optional_scopes) for applications - [#1060] Ensure that the native redirect_uri parameter matches with redirect_uri of the client
- [#1064] Add :before_successful_authorization and :after_successful_authorization hooks
- [#1069] Upgrade Bootstrap to 4 for Admin
- [#1068] Add rake task to cleanup databases that can become large over time
- [#1072] AuthorizationsController: Memoize strategy.authorize_response result to enable
subclasses to use the response object. - [#1075] Call
before_successful_authorizationandafter_successful_authorizationhooks
oncreateaction as well asnew - [#1082] Fix #916: remember routes mapping and use it required places (fix error with
customized Token Info route). - [#1086, #1088] Fix bug with receiving default scopes in the token even if they are
not present in the application scopes (use scopes intersection). - [#1076] Add config to enforce content type to application/x-www-form-urlencoded
- Fix bug with
force_ssl_in_redirect_uriwhen it breaks existing applications with an
SSL redirect_uri.
- Ruby
Published by nbulaj over 8 years ago
https://github.com/doorkeeper-gem/doorkeeper - v4.3.2
- [#1053] Support authorizing with query params in the request
redirect_uriif explicitly present in app'sApplication#redirect_uri
- Ruby
Published by nbulaj over 8 years ago
https://github.com/doorkeeper-gem/doorkeeper - v4.3.1
- Remove
BaseRecordand introduce additional concern for ordering methods to fix
braking changes for Doorkeeper models. - [#1032] Refactor BaseRequest callbacks into configurable lambdas
- [#1040] Clear mixins from ActiveRecord DSL and save only overridable API. It
allows to use this mixins in Doorkeeper ORM extensions with minimum code boilerplate.
- Ruby
Published by nbulaj over 8 years ago
https://github.com/doorkeeper-gem/doorkeeper - v4.2.6
- [#970] Escape certain attributes in authorization forms.
- Ruby
Published by nbulaj over 8 years ago
https://github.com/doorkeeper-gem/doorkeeper - v4.3.0
- [#976] Fix to invalidate the second redirect URI when the first URI is the native URI
- [#1035] Allow
Application#redirect_uri=to handle array of URIs. - [#1036] Allow to forbid Application redirect URI's with specific rules.
- [#1029] Deprecate
order_methodand introduceordered_by. Sort applications
bycreated_atin index action. - [#1033] Allow Doorkeeper configuration option #force_ssl_in_redirect_uri to be a callable object.
- Fix Grape integration & add specs for it
- [#913] Deferred ORM (ActiveRecord) models loading
- [#943] Fix Access Token token generation when certain errors occur in custom token generators
- [#1026] Implement RFC7662 - OAuth 2.0 Token Introspection
- [#985] Generate valid migration files for Rails >= 5
- [#972] Replace Struct subclassing with block-form initialization
- [#1003] Use URL query param to pass through native redirect auth code so automated apps can find it.
- [#868]
Scopes#&andScopes#+now take an array or any other enumerable
object. - [#1019] Remove translation not in use:
invalid_resource_owner. - Use Ruby 2 hash style syntax (min required Ruby version = 2.1)
- [#948] Make Scopes.<=> work with any "other" value.
- [#974] Redirect URI is checked without query params within AuthorizationCodeRequest.
- [#1004] More explicit help text for
native_redirect_uri. - [#1023] Update Ruby versions and test against 2.5.0 on Travis CI.
- [#1024] Migrate from FactoryGirl to FactoryBot.
- [#1025] Improve documentation for adding foreign keys
- [#1028] Make it possible to have composit strategy names.
- Ruby
Published by nbulaj over 8 years ago
https://github.com/doorkeeper-gem/doorkeeper - v4.2.5
- [#936] Deprecate
Doorkeeper#configured?,Doorkeeper#database_installed?, and
Doorkeeper#installed? - [#909] Add
InvalidTokenResponse#reasonreader method to allow read the kind
of invalid token error. - [#928] Test against more recent Ruby versions
- Small refactorings within the codebase
- [#921] Switch to Appraisal, and test against Rails master
- [#892] Add minimum Ruby version requirement
- Ruby
Published by maclover7 over 9 years ago
https://github.com/doorkeeper-gem/doorkeeper -
- Security fix: Address CVE-2016-6582, implement token revocation according to
spec (tokens might not be revoked if client follows the spec). - [#873] Add hooks to Doorkeeper::ApplicationMetalController
- [#871] Allow downstream users to better utilize doorkeeper spec factories by
eliminating name conflict on:userfactory.
- Ruby
Published by tute about 10 years ago
https://github.com/doorkeeper-gem/doorkeeper -
- [#845] Allow customising the
Doorkeeper::ApplicationControllerbase controller
- Ruby
Published by tute about 10 years ago
https://github.com/doorkeeper-gem/doorkeeper -
[#834] Fix AssetNotPrecompiled error with Sprockets 4
[#843] Revert "Fix validation error messages"
[#847] Specify Null option to timestamps
- Ruby
Published by tute about 10 years ago
https://github.com/doorkeeper-gem/doorkeeper -
- [#777] Add support for public client in password grant flow
- [#823] Make configuration and specs ORM independent
- [#745] Add created_at timestamp to token generation options
- [#838] Drop
Application#scopesgenerator and warning, introduced for
upgrading doorkeeper from v2 to v3. - [#801] Fix Rails 5 warning messages
- Test against Rails 5 RC1
- Ruby
Published by tute over 10 years ago
https://github.com/doorkeeper-gem/doorkeeper -
-
[#769] Revoke refresh token on access token use. To make use of the new config
addprevious_refresh_tokencolumn tooauth_access_tokens:rails generate doorkeeper:previous_refresh_token -
[#811] Toughen parameters filter with exact match
-
[#813] Applications admin bugfix
-
[#799] Fix Ruby Warnings
-
Drop
attr_accessiblefrom models
Backward incompatible changes
- [#730] Force all timezones to use UTC to prevent comparison issues.
- [#802] Remove
config.i18n.fallbacksfrom engine
- Ruby
Published by tute over 10 years ago
https://github.com/doorkeeper-gem/doorkeeper -
Backward incompatible changes
- [#678] Change application-specific scopes to take precedence over server-wide
scopes. This removes the previous behavior where the intersection between
application and server scopes was used. - [#648] Extracts mongodb ORMs to
https://github.com/doorkeeper-gem/doorkeeper-mongodb. If you use ActiveRecord
you don’t need to do any change, otherwise you will need to install the new
plugin. - [#665]
doorkeeper_unauthorized_render_options(error:)and
doorkeeper_forbidden_render_options(error:)now accepterrorkeyword
argument.
Other changes
- [#671] Fixes
NoMethodError - undefined method 'getlocal'when calling
the /oauth/token path. Switch from using a DateTime object to update
AR to using a Time object. (Issue #668) - [#677] Support editing application-specific scopes via the standard forms
- [#682] Pass error hash to Grape
error! - [#683] Generate application secret/UID if fields are blank strings
- Removes
doorkeeper_fordeprecation notice. - Remove
applications.scopesupgrade notice.
- Ruby
Published by tute over 10 years ago
https://github.com/doorkeeper-gem/doorkeeper -
- Fix optional belongs_to for Rails 5
- Ruby
Published by tute over 10 years ago
https://github.com/doorkeeper-gem/doorkeeper -
Backward incompatible changes
- Drops support for Rails 4.1 and earlier
- Drops support for Ruby 2.0
- [#778] Bug fix: use the remaining time that a token is still valid when
building the redirect URI for the implicit grant flow
Other changes
- [#771] Validation error messages fixes
- Adds foreign key constraints in generated migrations between tokens and
grants, and applications - Support Rails 5
- Ruby
Published by tute over 10 years ago
https://github.com/doorkeeper-gem/doorkeeper -
- [#712] Wrap exchange of grant token for access token and access token refresh
in transactions - [#704] Allow applications scopes to be mass assigned
- [#707] Fixed order of Mixin inclusion and table_name configuration in models
- [#712] Wrap access token and refresh grants in transactions
- Adds JRuby support
- Specs, views and documentation adjustments
- Ruby
Published by tute almost 11 years ago
https://github.com/doorkeeper-gem/doorkeeper -
- [#736] Existing valid tokens are now reused in client_credentials flow
- [#749] Allow user to raise authorization error with custom messages.
Underresource_owner_authenticatorblock a user can
raise Doorkeeper::Errors::DoorkeeperError.new('custom_message') - [#762] Check doesn’t abort the actual migration, so it runs
- [#722]
doorkeeper_forbidden_render_optionsnow supports returning a 404 by
specifyingrespond_not_found_when_forbidden: truein the
doorkeeper_forbidden_render_optionsmethod. - [#734] Simplify and remove duplication in request strategy classes
- Ruby
Published by tute almost 11 years ago