Problem
The engine adds its OIDC keys to filter_parameters as symbols (lib/activeadmin/oidc/engine.rb:121):
app.config.filter_parameters |= %i[code id_token access_token refresh_token state nonce]
ActiveSupport::ParameterFilter matches a symbol as a case-insensitive substring of the key, at any nesting depth. So the host app loses every non-secret param that contains code or state from its logs:
Parameters: {"data" => {"attributes" => {"status" => "Failed", "code_id" => "[FILTERED]", ...}}}
In our app this hid code_id, refuse_code, postal_code, state_eq (ransack filters), and onboarding_state.
A host can't fix this in config/initializers, because the engine's initializer runs after them. Today the workaround is a separate initializer with after: 'activeadmin_oidc.filter_parameters' that swaps the symbols out.
Proposed fix
Add the keys as anchored regexps, so they match only the exact key:
initializer 'activeadmin_oidc.filter_parameters' do |app|
# Anchored: a symbol matches as a substring, so :code would also hide a host's code_id.
oidc_params = %w[code state nonce id_token access_token refresh_token]
app.config.filter_parameters |= oidc_params.map { |key| /\A#{key}\z/i }
end
The OIDC callback params still get filtered, because the match is per key at any depth. Regexp#== compares source and options, so |= still deduplicates.
Also:
- Update the README (lines 77 and 375) to say the keys are matched exactly.
- Add a spec:
code and state are filtered; code_id and state_eq are not.
- Add a CHANGELOG entry.
Problem
The engine adds its OIDC keys to
filter_parametersas symbols (lib/activeadmin/oidc/engine.rb:121):ActiveSupport::ParameterFiltermatches a symbol as a case-insensitive substring of the key, at any nesting depth. So the host app loses every non-secret param that containscodeorstatefrom its logs:In our app this hid
code_id,refuse_code,postal_code,state_eq(ransack filters), andonboarding_state.A host can't fix this in
config/initializers, because the engine's initializer runs after them. Today the workaround is a separate initializer withafter: 'activeadmin_oidc.filter_parameters'that swaps the symbols out.Proposed fix
Add the keys as anchored regexps, so they match only the exact key:
The OIDC callback params still get filtered, because the match is per key at any depth.
Regexp#==compares source and options, so|=still deduplicates.Also:
codeandstateare filtered;code_idandstate_eqare not.