doorkeeper
https://github.com/doorkeeper-gem/doorkeeper
Ruby
Doorkeeper is an OAuth 2 provider for Ruby on Rails / Grape.
Triage Issues!
When you volunteer to triage issues, you'll receive an email each day with a link to an open issue that needs help in this project. You'll also receive instructions on how to triage issues.
Triage Docs!
Receive a documented method or class from your favorite GitHub repos in your inbox every day. If you're really pro, receive undocumented methods or classes and supercharge your commit history.
3 Subscribers
Add a CodeTriage badge to doorkeeper
Help out
- Issues
- Add experimental Client ID Metadata Documents support
- Client ID Metadata Documents (CIMDs)
- add dpop (rfc 9449) support
- Refresh tokens cannot reduce scopes correctly
- Support OAuth RFC - JWT for Client Authentication and Authorization Grants
- There is no way to refresh an access token without revoking the previous access token
- Refresh Tokens as-implemented are susceptible to Refresh Token Reuse Attacks
- Always requiring `redirect_uri` is not compliant to RFC 6749
- Better support for credential rotation
- Support OAuth DPoP
- Docs
- Doorkeeper::Errors::MultipleAccessTokenMethods#reason
- Doorkeeper::Errors::MultipleAccessTokenMethods#type
- Doorkeeper::OAuth::Token.parameter_sources
- Doorkeeper::OAuth::Token.transmission_methods_used
- Doorkeeper::Rails::Helpers#doorkeeper_bad_request_render_options
- Doorkeeper::Config::Validations#validate_private_key_jwt_identity
- Doorkeeper::TokenInfoController#doorkeeper_token_error_response
- Doorkeeper::Models::SecretStorable::ClassMethods#write_upgraded_secret
- Doorkeeper::Models::SecretStorable::ClassMethods#restore_matched_secret
- Doorkeeper::Config::Builder#validate_client_before_resource_owner_authentication