diff --git a/CHANGELOG.md b/CHANGELOG.md index 85492a1..009199c 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,20 @@ # Changelog -## Unreleased +## 3.0.1 -- Fix: the OIDC `filter_parameters` entries now match exact keys instead of substrings. `code_verifier`, `id_token`, `access_token` and `refresh_token` are filtered at any depth; `code`, `state`, `session_state` and `nonce` only at the top level. Host params such as `code_id`, `state_eq` or `order[state]` are no longer filtered from logs. If you relied on the old substring match to hide params like `invite_code` or `reset_code`, add them to your own `filter_parameters`. +- Fix: the OIDC `filter_parameters` entries now match exact keys instead of substrings. `code_verifier`, `id_token`, `access_token` and `refresh_token` are filtered at any depth; `code`, `state`, `session_state` and `nonce` only at the top level. Host params such as `code_id`, `state_eq` or `order[state]` are no longer hidden in logs (#26). + +### Check before upgrading: some params are no longer hidden in logs + +Up to 3.0.0, the engine hid every param whose name contained `code`, `state`, `nonce` or one of the token names, at any depth. After upgrading, these values are written to your logs in plain text: + +- params whose name only contains one of those words, such as `invite_code`, `reset_code`, `verification_code` or `oauth_state`; +- nested `code`, `state`, `session_state` and `nonce`, such as `user[code]`. + +If any of them carry a secret, add them to your own filters, for example in `config/initializers/filter_parameter_logging.rb`: + +```ruby +Rails.application.config.filter_parameters += %i[invite_code reset_code verification_code] +``` + +Your entries are kept alongside the engine's. If your app still has the Rails default list, names containing `token` stay hidden by its `:token` entry. diff --git a/lib/activeadmin/oidc/version.rb b/lib/activeadmin/oidc/version.rb index e8a3ed3..0733d3b 100644 --- a/lib/activeadmin/oidc/version.rb +++ b/lib/activeadmin/oidc/version.rb @@ -2,6 +2,6 @@ module ActiveAdmin module Oidc - VERSION = "3.0.0" + VERSION = "3.0.1" end end