Download Latest Version v5.9.9 source code.zip (378.3 kB) Google Add to Preferred Sources
Home / v5.9.9
Name Modified Size InfoDownloads / Week
Parent folder
README.md 2026-09-24 1.9 kB
v5.9.9 source code.tar.gz 2026-09-24 219.9 kB
v5.9.9 source code.zip 2026-09-24 378.3 kB
Totals: 3 Items   600.2 kB 0
  • Fix: AuthorizedApplicationsController now answers 401 Unauthorized instead of running with a nil resource owner, which listed and revoked every token that has no resource owner — the ones the client credentials flow issues. Affected host applications are those whose resource_owner_authenticator answers nil without halting the request itself; the generated initializer's example redirects and is not affected.
  • Fix: AuthorizationsController#destroy now validates the client and redirect URI before producing the deny response, and renders — never redirects — when validation fails. Previously the deny path performed no OAuth-layer validation at all, allowing an open redirect to an attacker-controlled origin with the OAuth state attached. Also reject unregistered response_type values on the authorization endpoint rather than resolving them through the constantize fallback.
  • Fix: refuse redirect URIs with a script scheme (javascript, vbscript, data) both when an application is registered and at authorization time, regardless of forbid_redirect_uri. Such a URI is never a legitimate redirection endpoint, and with response_mode=form_post it became the action of the auto-submitting form the authorization server renders on its own origin. Already stored records with such a URI are now refused with invalid_redirect_uri before the consent screen is shown.
  • [#1938] Fix: a request body ActionDispatch cannot parse (malformed JSON under a JSON content type, say) no longer raises ActionDispatch::Http::Parameters::ParseError out of Doorkeeper::OAuth::Token.from_request and doorkeeper_token. Since 5.9.7 the RFC 6750 §2 multi-method check read the body on every request, so such a request raised even when it carried a valid Bearer header. The body is now treated as carrying no token, the same way ActionDispatch's own #filtered_parameters treats that error.
Source: README.md, updated 2026-09-24