doorkeeper
https://github.com/doorkeeper-gem/doorkeeper
Ruby
Doorkeeper is an OAuth 2 provider for Ruby on Rails / Grape.
Triage Issues!
When you volunteer to triage issues, you'll receive an email each day with a link to an open issue that needs help in this project. You'll also receive instructions on how to triage issues.
Triage Docs!
Receive a documented method or class from your favorite GitHub repos in your inbox every day. If you're really pro, receive undocumented methods or classes and supercharge your commit history.
3 Subscribers
Add a CodeTriage badge to doorkeeper
Help out
- Issues
- Add experimental Client ID Metadata Documents support
- Add opt-in client secret rotation with a grace period
- Add `public_client_access_token_expires_in` configuration option (OAuth 2.1 §2.4)
- Improving publishing security?
- Public Clients and security exposure (OAuth 2.1)
- Client ID Metadata Documents (CIMDs)
- add dpop (rfc 9449) support
- Support OAuth RFC - JWT for Client Authentication and Authorization Grants
- There is no way to refresh an access token without revoking the previous access token
- Refresh Tokens as-implemented are susceptible to Refresh Token Reuse Attacks
- Docs
- AccountOwnedConcern#temporary_suspension_response
- AccountOwnedConcern#permanent_suspension_response
- AccountOwnedConcern#skip_temporary_suspension_response?
- AccountOwnedConcern#check_account_suspension
- AccountOwnedConcern#check_account_confirmation
- AccountOwnedConcern#check_account_approval
- AccountOwnedConcern#username_param
- AccountOwnedConcern#set_account
- AccountOwnedConcern#account_required?
- Admin::RelationshipsController#filter_params