Skip to content

filter_parameters symbols hide host params like code_id and state_eq #26

Description

@senid231

Problem

The engine adds its OIDC keys to filter_parameters as symbols (lib/activeadmin/oidc/engine.rb:121):

app.config.filter_parameters |= %i[code id_token access_token refresh_token state nonce]

ActiveSupport::ParameterFilter matches a symbol as a case-insensitive substring of the key, at any nesting depth. So the host app loses every non-secret param that contains code or state from its logs:

Parameters: {"data" => {"attributes" => {"status" => "Failed", "code_id" => "[FILTERED]", ...}}}

In our app this hid code_id, refuse_code, postal_code, state_eq (ransack filters), and onboarding_state.

A host can't fix this in config/initializers, because the engine's initializer runs after them. Today the workaround is a separate initializer with after: 'activeadmin_oidc.filter_parameters' that swaps the symbols out.

Proposed fix

Add the keys as anchored regexps, so they match only the exact key:

initializer 'activeadmin_oidc.filter_parameters' do |app|
  # Anchored: a symbol matches as a substring, so :code would also hide a host's code_id.
  oidc_params = %w[code state nonce id_token access_token refresh_token]
  app.config.filter_parameters |= oidc_params.map { |key| /\A#{key}\z/i }
end

The OIDC callback params still get filtered, because the match is per key at any depth. Regexp#== compares source and options, so |= still deduplicates.

Also:

  • Update the README (lines 77 and 375) to say the keys are matched exactly.
  • Add a spec: code and state are filtered; code_id and state_eq are not.
  • Add a CHANGELOG entry.

Metadata

Metadata

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions