| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| README.md | 2026-09-24 | 1.9 kB | |
| v5.9.9 source code.tar.gz | 2026-09-24 | 219.9 kB | |
| v5.9.9 source code.zip | 2026-09-24 | 378.3 kB | |
| Totals: 3 Items | 600.2 kB | 0 | |
- Fix:
AuthorizedApplicationsControllernow answers401 Unauthorizedinstead of running with anilresource owner, which listed and revoked every token that has no resource owner — the ones the client credentials flow issues. Affected host applications are those whoseresource_owner_authenticatoranswersnilwithout halting the request itself; the generated initializer's example redirects and is not affected. - Fix:
AuthorizationsController#destroynow validates the client and redirect URI before producing the deny response, and renders — never redirects — when validation fails. Previously the deny path performed no OAuth-layer validation at all, allowing an open redirect to an attacker-controlled origin with the OAuthstateattached. Also reject unregisteredresponse_typevalues on the authorization endpoint rather than resolving them through theconstantizefallback. - Fix: refuse redirect URIs with a script scheme (
javascript,vbscript,data) both when an application is registered and at authorization time, regardless offorbid_redirect_uri. Such a URI is never a legitimate redirection endpoint, and withresponse_mode=form_postit became the action of the auto-submitting form the authorization server renders on its own origin. Already stored records with such a URI are now refused withinvalid_redirect_uribefore the consent screen is shown. - [#1938] Fix: a request body ActionDispatch cannot parse (malformed JSON under a JSON content type, say) no longer raises
ActionDispatch::Http::Parameters::ParseErrorout ofDoorkeeper::OAuth::Token.from_requestanddoorkeeper_token. Since 5.9.7 the RFC 6750 §2 multi-method check read the body on every request, so such a request raised even when it carried a valid Bearer header. The body is now treated as carrying no token, the same way ActionDispatch's own#filtered_parameterstreats that error.