Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
19 changes: 17 additions & 2 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,20 @@
# Changelog

## Unreleased
## 3.0.1

- Fix: the OIDC `filter_parameters` entries now match exact keys instead of substrings. `code_verifier`, `id_token`, `access_token` and `refresh_token` are filtered at any depth; `code`, `state`, `session_state` and `nonce` only at the top level. Host params such as `code_id`, `state_eq` or `order[state]` are no longer filtered from logs. If you relied on the old substring match to hide params like `invite_code` or `reset_code`, add them to your own `filter_parameters`.
- Fix: the OIDC `filter_parameters` entries now match exact keys instead of substrings. `code_verifier`, `id_token`, `access_token` and `refresh_token` are filtered at any depth; `code`, `state`, `session_state` and `nonce` only at the top level. Host params such as `code_id`, `state_eq` or `order[state]` are no longer hidden in logs (#26).

### Check before upgrading: some params are no longer hidden in logs

Up to 3.0.0, the engine hid every param whose name contained `code`, `state`, `nonce` or one of the token names, at any depth. After upgrading, these values are written to your logs in plain text:

- params whose name only contains one of those words, such as `invite_code`, `reset_code`, `verification_code` or `oauth_state`;
- nested `code`, `state`, `session_state` and `nonce`, such as `user[code]`.

If any of them carry a secret, add them to your own filters, for example in `config/initializers/filter_parameter_logging.rb`:

```ruby
Rails.application.config.filter_parameters += %i[invite_code reset_code verification_code]
```

Your entries are kept alongside the engine's. If your app still has the Rails default list, names containing `token` stay hidden by its `:token` entry.
2 changes: 1 addition & 1 deletion lib/activeadmin/oidc/version.rb
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,6 @@

module ActiveAdmin
module Oidc
VERSION = "3.0.0"
VERSION = "3.0.1"
end
end
Loading