From notifications at github.com Thu Oct 1 00:03:16 2026 From: notifications at github.com (Tom Hughes) Date: Wed, 30 Sep 2026 17:03:16 -0700 Subject: [openstreetmap/openstreetmap-website] Bump brace-expansion from 5.0.8 to 5.0.12 (PR #7447) In-Reply-To: References: Message-ID: Merged #7447 into master. -- Reply to this email directly or view it on GitHub: https://github.com/openstreetmap/openstreetmap-website/pull/7447#event-32209942792 You are receiving this because you are subscribed to this thread. Message ID: -------------- next part -------------- An HTML attachment was scrubbed... URL: From notifications at github.com Thu Oct 1 06:06:30 2026 From: notifications at github.com (Andy Allan) Date: Wed, 30 Sep 2026 23:06:30 -0700 Subject: [openstreetmap/openstreetmap-website] Prevent percent characters being used in email addresses (PR #7442) In-Reply-To: References: Message-ID: Merged #7442 into master. -- Reply to this email directly or view it on GitHub: https://github.com/openstreetmap/openstreetmap-website/pull/7442#event-32226356514 You are receiving this because you are subscribed to this thread. Message ID: -------------- next part -------------- An HTML attachment was scrubbed... URL: From notifications at github.com Thu Oct 1 06:06:42 2026 From: notifications at github.com (Andy Allan) Date: Wed, 30 Sep 2026 23:06:42 -0700 Subject: [openstreetmap/openstreetmap-website] Prevent percent characters being used in email addresses (PR #7442) In-Reply-To: References: Message-ID: gravitystorm left a comment (openstreetmap/openstreetmap-website#7442) Merged, thanks! -- Reply to this email directly or view it on GitHub: https://github.com/openstreetmap/openstreetmap-website/pull/7442#issuecomment-5925740757 You are receiving this because you are subscribed to this thread. Message ID: -------------- next part -------------- An HTML attachment was scrubbed... URL: From notifications at github.com Thu Oct 1 07:16:30 2026 From: notifications at github.com (Tom Hughes) Date: Thu, 01 Oct 2026 00:16:30 -0700 Subject: [openstreetmap/openstreetmap-website] Avoid trying to detach a record connected by a composite key (PR #7448) Message-ID: This is intended to resolve the rails 8.1.3.1 test failures in #7444. The problem is that using `tag.old_node = nil` to detach the old node record from a tag doesn't really work even in the current version of rails - if you try that in the console in the current version you'll see that afterwards the `node_id` and `version` fields are still set while if you try it with a node tag record you'll find the key fields have been changed. Having said that current versions of rails seem to have some sort of cached record link as well which does get broken allowing the tests to work but that seems to have stopped in the new version. This PR creates the records without an attached object in the first place rather than trying to detach it later and also makes a few minor optimisations to the old tag model tests for good measure. You can view, comment on, or merge this pull request online at: https://github.com/openstreetmap/openstreetmap-website/pull/7448 -- Commit Summary -- * Avoid persisting test records unecessarily * Set attributes during record build where possible -- File Changes -- M test/models/old_node_tag_test.rb (13) M test/models/old_relation_tag_test.rb (13) M test/models/old_way_tag_test.rb (13) -- Patch Links -- https://github.com/openstreetmap/openstreetmap-website/pull/7448.patch https://github.com/openstreetmap/openstreetmap-website/pull/7448.diff -- Reply to this email directly or view it on GitHub: https://github.com/openstreetmap/openstreetmap-website/pull/7448 You are receiving this because you are subscribed to this thread. Message ID: -------------- next part -------------- An HTML attachment was scrubbed... URL: From notifications at github.com Thu Oct 1 07:22:39 2026 From: notifications at github.com (Tom Hughes) Date: Thu, 01 Oct 2026 00:22:39 -0700 Subject: [openstreetmap/openstreetmap-website] Exclude all rails gems from the main dependabot group (PR #7449) Message-ID: Changing `dependency-type` to `all` for dependabot in #7380 has caused #7446 to try and upgrade rails, which it wasn't meant to do. This attempts to fix that. You can view, comment on, or merge this pull request online at: https://github.com/openstreetmap/openstreetmap-website/pull/7449 -- Commit Summary -- * Exclude all rails gems from the main dependabot group -- File Changes -- M .github/dependabot.yml (12) -- Patch Links -- https://github.com/openstreetmap/openstreetmap-website/pull/7449.patch https://github.com/openstreetmap/openstreetmap-website/pull/7449.diff -- Reply to this email directly or view it on GitHub: https://github.com/openstreetmap/openstreetmap-website/pull/7449 You are receiving this because you are subscribed to this thread. Message ID: -------------- next part -------------- An HTML attachment was scrubbed... URL: From notifications at github.com Thu Oct 1 10:08:09 2026 From: notifications at github.com (Andy Allan) Date: Thu, 01 Oct 2026 03:08:09 -0700 Subject: [openstreetmap/openstreetmap-website] Exclude all rails gems from the main dependabot group (PR #7449) In-Reply-To: References: Message-ID: Merged #7449 into master. -- Reply to this email directly or view it on GitHub: https://github.com/openstreetmap/openstreetmap-website/pull/7449#event-32241361678 You are receiving this because you are subscribed to this thread. Message ID: -------------- next part -------------- An HTML attachment was scrubbed... URL: From notifications at github.com Thu Oct 1 10:08:04 2026 From: notifications at github.com (Andy Allan) Date: Thu, 01 Oct 2026 03:08:04 -0700 Subject: [openstreetmap/openstreetmap-website] Exclude all rails gems from the main dependabot group (PR #7449) In-Reply-To: References: Message-ID: gravitystorm left a comment (openstreetmap/openstreetmap-website#7449) It's a pity they aren't all named "rails*" like the rubocop ones! I'm happy to merge this. I do wonder a little bit if we're still gaining much by treating the rails dependabot group separately from the other gems, now that dependabot is respecting the `~> 8.1.0` in the Gemfile. It might be worth just putting them all into one dependabot group. -- Reply to this email directly or view it on GitHub: https://github.com/openstreetmap/openstreetmap-website/pull/7449#issuecomment-5929223541 You are receiving this because you are subscribed to this thread. Message ID: -------------- next part -------------- An HTML attachment was scrubbed... URL: From notifications at github.com Thu Oct 1 10:10:08 2026 From: notifications at github.com (Andy Allan) Date: Thu, 01 Oct 2026 03:10:08 -0700 Subject: [openstreetmap/openstreetmap-website] Avoid trying to detach a record connected by a composite key (PR #7448) In-Reply-To: References: Message-ID: gravitystorm left a comment (openstreetmap/openstreetmap-website#7448) LGTM, thanks! -- Reply to this email directly or view it on GitHub: https://github.com/openstreetmap/openstreetmap-website/pull/7448#issuecomment-5929252776 You are receiving this because you are subscribed to this thread. Message ID: -------------- next part -------------- An HTML attachment was scrubbed... URL: From notifications at github.com Thu Oct 1 10:09:15 2026 From: notifications at github.com (dependabot[bot]) Date: Thu, 01 Oct 2026 03:09:15 -0700 Subject: [openstreetmap/openstreetmap-website] Bump rails from 8.1.3.1 to 8.1.4 in the rails group across 1 directory (PR #7444) In-Reply-To: References: Message-ID: @dependabot[bot] pushed 1 commit. 45c53d910d7337fc635f9760b34d7dcb94fa0db1 Bump rails from 8.1.3.1 to 8.1.4 in the rails group across 1 directory -- View it on GitHub: https://github.com/openstreetmap/openstreetmap-website/pull/7444/changes/f7afeb6f8d48cf4c60bd00a873726f005861663e..45c53d910d7337fc635f9760b34d7dcb94fa0db1 You are receiving this because you are subscribed to this thread. Message ID: -------------- next part -------------- An HTML attachment was scrubbed... URL: From notifications at github.com Thu Oct 1 10:09:58 2026 From: notifications at github.com (Andy Allan) Date: Thu, 01 Oct 2026 03:09:58 -0700 Subject: [openstreetmap/openstreetmap-website] Avoid trying to detach a record connected by a composite key (PR #7448) In-Reply-To: References: Message-ID: Merged #7448 into master. -- Reply to this email directly or view it on GitHub: https://github.com/openstreetmap/openstreetmap-website/pull/7448#event-32241481459 You are receiving this because you are subscribed to this thread. Message ID: -------------- next part -------------- An HTML attachment was scrubbed... URL: From notifications at github.com Thu Oct 1 10:17:48 2026 From: notifications at github.com (dependabot[bot]) Date: Thu, 01 Oct 2026 03:17:48 -0700 Subject: [openstreetmap/openstreetmap-website] Bump the dependencies group with 24 updates (PR #7446) In-Reply-To: References: Message-ID: dependabot[bot] left a comment (openstreetmap/openstreetmap-website#7446) Looks like these dependencies are updatable in another way, so this is no longer needed. -- Reply to this email directly or view it on GitHub: https://github.com/openstreetmap/openstreetmap-website/pull/7446#issuecomment-5929364275 You are receiving this because you are subscribed to this thread. Message ID: -------------- next part -------------- An HTML attachment was scrubbed... URL: From notifications at github.com Thu Oct 1 10:17:52 2026 From: notifications at github.com (dependabot[bot]) Date: Thu, 01 Oct 2026 03:17:52 -0700 Subject: [openstreetmap/openstreetmap-website] Bump the dependencies group with 24 updates (PR #7446) In-Reply-To: References: Message-ID: Closed #7446. -- Reply to this email directly or view it on GitHub: https://github.com/openstreetmap/openstreetmap-website/pull/7446#event-32241985711 You are receiving this because you are subscribed to this thread. Message ID: -------------- next part -------------- An HTML attachment was scrubbed... URL: From notifications at github.com Thu Oct 1 10:18:17 2026 From: notifications at github.com (dependabot[bot]) Date: Thu, 01 Oct 2026 03:18:17 -0700 Subject: [openstreetmap/openstreetmap-website] Bump the dependencies group across 1 directory with 12 updates (PR #7450) Message-ID: Bumps the dependencies group with 12 updates in the / directory: | Package | From | To | | --- | --- | --- | | [activerecord-postgis](https://github.com/seuros/activerecord-postgis) | `0.6.0` | `0.6.1` | | [actionpack-page_caching](https://github.com/rails/actionpack-page_caching) | `1.2.4` | `1.2.5` | | [doorkeeper](https://github.com/doorkeeper-gem/doorkeeper) | `5.9.7` | `5.9.9` | | [doorkeeper-openid_connect](https://github.com/doorkeeper-gem/doorkeeper-openid_connect) | `1.10.5` | `2.0.0` | | [dalli](https://github.com/petergoldstein/dalli) | `5.1.0` | `5.1.1` | | [aws-sdk-s3](https://github.com/aws/aws-sdk-ruby) | `1.232.1` | `1.232.2` | | [herb](https://github.com/marcoroth/herb) | `0.10.4` | `0.11.0` | | [simplecov](https://github.com/simplecov-ruby/simplecov) | `1.3.0` | `1.3.1` | | [database_consistency](https://github.com/djezzzl/database_consistency) | `3.0.12` | `3.0.13` | | [aws-partitions](https://github.com/aws/aws-sdk-ruby) | `1.1289.0` | `1.1291.0` | | [bindata](https://github.com/dmendel/bindata) | `3.0.0` | `3.0.1` | | [rdoc](https://github.com/ruby/rdoc) | `8.0.0` | `8.1.0` | Updates `activerecord-postgis` from 0.6.0 to 0.6.1
Release notes

Sourced from activerecord-postgis's releases.

activerecord-postgis: v0.6.1

0.6.1 (2026-09-22)

Bug Fixes

  • don't memoize RGeo factory in spatial types (#20) (d9e9f08)
Changelog

Sourced from activerecord-postgis's changelog.

0.6.1 (2026-09-22)

Bug Fixes

  • don't memoize RGeo factory in spatial types (#20) (d9e9f08)
Commits

Updates `actionpack-page_caching` from 1.2.4 to 1.2.5
Changelog

Sourced from actionpack-page_caching's changelog.

1.2.5 (September 21, 2026)

  • Fix directory check for directory with shared prefix

John Hawthorn

Commits

Updates `doorkeeper` from 5.9.7 to 5.9.9
Release notes

Sourced from doorkeeper's releases.

v5.9.9

  • Fix: AuthorizedApplicationsController now answers 401 Unauthorized instead of running with a nil resource owner, which listed and revoked every token that has no resource owner ? the ones the client credentials flow issues. Affected host applications are those whose resource_owner_authenticator answers nil without halting the request itself; the generated initializer's example redirects and is not affected.
  • Fix: AuthorizationsController#destroy now validates the client and redirect URI before producing the deny response, and renders ? never redirects ? when validation fails. Previously the deny path performed no OAuth-layer validation at all, allowing an open redirect to an attacker-controlled origin with the OAuth state attached. Also reject unregistered response_type values on the authorization endpoint rather than resolving them through the constantize fallback.
  • Fix: refuse redirect URIs with a script scheme (javascript, vbscript, data) both when an application is registered and at authorization time, regardless of forbid_redirect_uri. Such a URI is never a legitimate redirection endpoint, and with response_mode=form_post it became the action of the auto-submitting form the authorization server renders on its own origin. Already stored records with such a URI are now refused with invalid_redirect_uri before the consent screen is shown.
  • #1938 Fix: a request body ActionDispatch cannot parse (malformed JSON under a JSON content type, say) no longer raises ActionDispatch::Http::Parameters::ParseError out of Doorkeeper::OAuth::Token.from_request and doorkeeper_token. Since 5.9.7 the RFC 6750 ?2 multi-method check read the body on every request, so such a request raised even when it carried a valid Bearer header. The body is now treated as carrying no token, the same way ActionDispatch's own #filtered_parameters treats that error.
Changelog

Sourced from doorkeeper's changelog.

Changelog

See https://github.com/doorkeeper-gem/doorkeeper/wiki/Migration-from-old-versions for upgrade guides.

User-visible changes worth mentioning.

main

  • [#PR ID] Description of the change.
  • #1960 Ignore the port of http://localhost redirect URIs like that of loopback IP literals (RFC 8252 ?7.3 / ?8.3).
  • #1959 A custom access_token_generator now receives the token's resource (RFC 8707), so a JWT generator can set aud.

6.0.0.rc2

Please make sure you read the Upgrade guides and changelog below before the update since this version includes breaking changes.

  • #1951 Fix: the built gem no longer contains vendor/bundle. The gemspec globed all of vendor/, which swept in the bundle installed by the release workflow; 6.0.0.rc1 is a 44.4 MB download against 154 KB for 6.0.0.beta2.
  • Fix: AuthorizedApplicationsController now answers 401 Unauthorized instead of running with a nil resource owner, which listed and revoked every token that has no resource owner ? the ones the client credentials flow issues. Affected host applications are those whose resource_owner_authenticator answers nil without halting the request itself; the generated initializer's example redirects and is not affected.
  • Fix: AuthorizationsController#destroy now validates the client and redirect URI before producing the deny response, and renders ? never redirects ? when validation fails. Previously the deny path performed no OAuth-layer validation at all, allowing an open redirect to an attacker-controlled origin with the OAuth state attached. Also reject unregistered response_type values on the authorization endpoint rather than resolving them through the constantize fallback.
  • Fix: refuse redirect URIs with a script scheme (javascript, vbscript, data) both when an application is registered and at authorization time, regardless of forbid_redirect_uri. Such a URI is never a legitimate redirection endpoint, and with response_mode=form_post it became the action of the auto-submitting form the authorization server renders on its own origin. Already stored records with such a URI are now refused with invalid_redirect_uri before the consent screen is shown.
  • #1932 Fix: keep the scope originally granted by the resource owner on refresh tokens (RFC 6749 ?6), so a chain narrowed on one refresh can return to its granted scope. Tracked in a new refresh_token_scopes column; existing installations opt in with rails generate doorkeeper:refresh_token_scopes.
  • #1933 Warn at boot when the implicit or password grant flow is enabled: both are deprecated by RFC 9700 (OAuth 2.0 Security BCP) and removed from OAuth 2.1, and may be removed in a future Doorkeeper release.
  • #1915 Fix: fetching a client's jwks_uri now falls back to the other addresses returned by DNS when the first one cannot be connected to.
  • #1934 The refresh_token grant now consults custom_access_token_expires_in (with Doorkeeper::OAuth::REFRESH_TOKEN as the context grant type) for the TTL of the refreshed access token. A callable that returns nil for this grant, or no callable at all, keeps inheriting the TTL of the token being refreshed as before. A callable that returns a value unconditionally now applies to refreshes as well.
  • #1935 Add opt-in public_client_access_token_expires_in configuration option: a ceiling for the lifetime of access tokens issued to public (non-confidential) clients by any grant, refresh_token included, as OAuth 2.1 Section 2.4 requires the exposure of tokens issued to unauthenticated clients to be limited. Confidential clients are not affected.
  • #1938 Fix: a request body ActionDispatch cannot parse (malformed JSON under a JSON content type, say) no longer raises ActionDispatch::Http::Parameters::ParseError out of Doorkeeper::OAuth::Token.from_request and doorkeeper_token. Since 5.9.7 the RFC 6750 ?2 multi-method check read the body on every request, so such a request raised even when it carried a valid Bearer header. The body is now treated as carrying no token, the same way ActionDispatch's own #filtered_parameters treats that error.
  • #1950 Document hash_token_secrets / hash_application_secrets fallback: as a migration-period setting that should be removed once every row is hashed, and warn at boot for as long as one is configured. While a :plain fallback is active the stored value is itself a valid credential, so those columns need protecting as carefully as plaintext ones.
  • #1953 Fix: public_client_access_token_expires_in now also holds under reuse_access_token and with String TTLs, and the refresh_token grant hands custom_access_token_expires_in and resource_indicator_validator what every other grant does.

6.0.0.rc1

Please make sure you read the Upgrade guides and changelog below before the update since this version includes breaking changes.

  • Require Ruby >= 3.2 in the gemspec, matching the CI matrix (3.2 / 3.3 / 3.4 / 4.0). Ruby 2.7, 3.0 and 3.1 have reached end-of-life.
  • Fix: the client_secret_basic strategy now requires a client_id sent in the request body to name the same client as the Authorization: Basic header ? the RFC 7521 ?4.2 agreement check private_key_jwt already applies to an assertion's issuer. A request presenting Basic credentials for one client and a client_id for another was authenticated as the Basic client, silently discarding the other identity. A bare client_id is not a client authentication method of its own, so the RFC 6749 ?2.3 multiple-methods check does not (and should not) count it.
  • #1906 Internal: exempt Doorkeeper::Config from Metrics/ClassLength with a directive on the class itself instead of raising the cop's global ceiling, so adding a configuration option no longer trips the limit.
  • #1907 Fix: a resource parameter no longer produces a 500 at the authorization endpoint when resource_indicator_validator is configured without the doorkeeper:resource_indicators migration. Such a request is now answered with server_error, as the token endpoint already did, and the missing migration is warned about at boot.
  • #1909 Add Rails 8.1 to CI test matrix.
  • #1910 Add opt-in validate_client_before_resource_owner_authentication configuration option: the authorization endpoint validates client_id and redirect_uri before authenticating the resource owner, so users are not sent through login for a request that can only fail.
  • #1916 Fix broken Coveralls coverage reporting.
  • #1918 The api_only controller specs no longer load the real controller sources, which detached the coverage of every other example that ran them and made the reported coverage depend on the random example order.
  • #1923 Fix: the fallback secret upgrade no longer writes the matched secret back over a value stored in the meantime, which could undo a concurrent #renew_secret and leave the superseded secret valid. Active Record writes the upgrade conditionally on the column still holding the value that matched; other ORMs can implement the new write_upgraded_secret hook. The Active Record write is a single update_all statement, so model callbacks and validations no longer run on this upgrade (timestamps and optimistic locking are still maintained).
  • #1925 Internal: pin the development dependency on json below 3.0. json 3 removed the positional options Hash from JSON.parse and the quirks_mode option from JSON.generate, both of which Active Support still uses, so the suite could not run on any released Rails version.
  • #1926 [BREAKING] Fix: private_key_jwt client authentication no longer accepts an audience derived from the request's Host header, which let a client assertion minted for another authorization server be replayed here. A server that configures neither issuer nor Rails' default_url_options[:host] now has no acceptable audience and refuses every assertion, and is warned about it at boot.
  • [BREAKING] Refuse requests that transmit the access token by more than one method (RFC 6750 ?2) with an invalid_request error, instead of silently authorizing with the first method that yielded a token and discarding the rest. The form-encoded body (?2.2) and the URI query (?2.3) count as two methods even though Rails and Rack merge them into a single params hash, and the same token repeated across two methods is refused too ? ?2 forbids the second method, not a disagreement between the two.
    • Only the built-in extraction methods take part in the check; a custom callable in access_token_methods keeps the historical first-wins behavior and is never invoked more than once.
    • Doorkeeper::OAuth::Token.from_request / .authenticate raise Doorkeeper::Errors::MultipleAccessTokenMethods. Doorkeeper.authenticate and every doorkeeper_token helper (Rails, Grape, and Doorkeeper's own controllers) keep their token-or-nil contract, so doorkeeper_authorize! renders the refusal through a new doorkeeper_bad_request_render_options(error:) hook (head 400 unless you override it).

... (truncated)

Commits
  • 6f65d41 Backport gemspec to avoid vendor/bundle
  • 1879ce4 Release 5.9.9 :tada:
  • 9403233 Merge commit from fork
  • 6d711eb Merge commit from fork
  • 7504992 Refuse redirect URIs with a script scheme
  • de57e75 Merge commit from fork
  • 0960bd7 Merge back release workflow for 5.9 branch
  • 9cafb36 Validate the client and redirect URI on the authorization deny path
  • f6ec046 Refuse authorized applications requests with no resource owner
  • e72e53f Merge pull request #1939 from doorkeeper-gem/chore/bump-5.9.8
  • Additional commits viewable in compare view

Updates `doorkeeper-openid_connect` from 1.10.5 to 2.0.0
Release notes

Sourced from doorkeeper-openid_connect's releases.

v2.0.0

  • Security: Register a dynamically registered client with the server's default_scopes when the registration request omits scope, instead of persisting an empty scope set. Only deployments that enable dynamic_client_registration are affected.
  • #364 Breaking: Require id_token_class / user_info_class overrides to inherit from Doorkeeper::OpenidConnect::IdToken / UserInfo (#344). Adds an IdToken#select_key hook returning the signing key and its algorithm together (IdToken::SigningKey) for per-client, rotating or multi-tenant keys, and binds the at_hash digest to that algorithm (OIDC Core ?3.2.2.10) rather than the global signing_algorithm
  • #387 Breaking: Remove the deprecated jws_private_key and jws_public_key initializer settings
  • #399 Breaking: Rename Doorkeeper::OpenidConnect::HybridIdTokenConcern to AtHashConcern. The old name described the id_token token response type as a hybrid flow, but OpenID Connect Core defines that response type under the Implicit Flow (?3.2) ? the Hybrid Flow response types of ?3.3 are not implemented by this gem. Removed without an alias: the constant only ever shipped in 2.0.0.beta1

v2.0.0.beta1

[!IMPORTANT]

  • This is a prerelease. RubyGems does not resolve prereleases from an unqualified requirement, so it must be requested explicitly: gem "doorkeeper-openid_connect", "2.0.0.beta1"
  • Migration required: existing installations must add the post_logout_redirect_uris column ? rails generate doorkeeper:openid_connect:add_post_logout_redirect_uris followed by rails db:migrate (#243)
  • Breaking (hybrid response type): the id_token token response object is now the configured id_token_class extended with HybridIdTokenConcern, and a custom id_token_class must expose an #access_token reader (#337)
  • Breaking (constant removed): Doorkeeper::OpenidConnect::IdTokenToken is gone ? custom subclasses must subclass IdToken and include HybridIdTokenConcern (#338)
  • Breaking (Dynamic Client Registration): a registration request that omits response_types / grant_types now defaults to ["code"] / ["authorization_code"] per RFC 7591 ?2, instead of inheriting the server's global configuration (#350)

Migration from Old Versions walks through each one.

  • #243 Add per-client post_logout_redirect_uris for RP-Initiated Logout, exposed via Doorkeeper::Application#post_logout_redirect_uris and #valid_post_logout_redirect_uri?(uri). URIs are validated with the same rules as redirect_uri; Dynamic Client Registration accepts and echoes them back
  • #320 Support mounting the engine under multiple named scopes ? use_doorkeeper_openid_connect as: :users makes each mount's discovery document advertise its own endpoints (#192)
  • #322 Fall back to Doorkeeper's issuer configuration when the OpenID Connect issuer is not set. The OpenID Connect value still takes precedence (#321)
  • #323 Resolve token_endpoint_auth_methods_supported from Doorkeeper's client authentication methods registry when available, falling back to legacy client_credentials_methods on older versions
  • #332 Fix grant_types_supported listing refresh_token twice when enabled via both grant_flows and use_refresh_token
  • #333 Emit the RFC 9207 iss parameter on id_token / id_token token authorization responses and on OIDC error redirects, and advertise authorization_response_iss_parameter_supported in the discovery document. No behavior change until Doorkeeper is configured with an issuer
  • #334 Allow Doorkeeper 6.0 (>= 5.5, < 7.0). Note: Doorkeeper 6.0's force_pkce applies to confidential clients too ? id_token / id_token token authorization requests are rejected unless they carry a code_challenge
  • #335 Add id_token_class and user_info_class config options for custom ID Token / UserInfo response objects
  • #337 Rework id_token_class / user_info_class internals ? lazy-resolve and validate configured classes at first use (fixes zeitwerk on Rails 7+) ? and deprecate Doorkeeper::OpenidConnect::IdTokenToken. A custom id_token_class must now expose an #access_token reader. Breaking (type change): the hybrid response token is now the configured id_token_class extended with HybridIdTokenConcern ? see the migration guide
  • #338 Breaking: Remove the deprecated IdTokenToken class. Custom subclasses must subclass IdToken and include HybridIdTokenConcern instead
  • #341 Fix dynamic client registration to respect the application_class configuration
  • #347 Omit symmetric (oct) keys from the JWKS endpoint when signing with an HMAC algorithm (RFC 7517)
  • #348 Authorization endpoint hardening:
    • Treat a malformed max_age parameter (e.g. max_age[]=1) as absent instead of a 500
    • Build prompt=login / prompt=select_account return URLs without mutating the shared request.query_parameters hash
    • Route internal errors (e.g. InvalidConfiguration) to a 500 instead of leaking them as authorization error redirects
  • #349 Fix several 500 errors in the claims pipeline: gracefully omit id_token when the access token has no resource owner, no application, or an owner that no longer resolves; return 401 invalid_token at userinfo for the same cases. Also dispatch claims whose response: option is configured with strings (e.g. response: ["id_token"]), which were previously dropped from every response
  • #350 Discovery / Dynamic Client Registration spec compliance:
    • Advertise the standard implicit grant type instead of the internal implicit_oidc name (RFC 7591 ?2)
    • Breaking: omitted response_types / grant_types in a registration request now default to ["code"] / ["authorization_code"] per RFC 7591 ?2
    • Use RFC 7591 ?3.2.2 error codes (invalid_redirect_uri / invalid_client_metadata) instead of the invented invalid_client_params
    • Serve WebFinger as application/jrd+json with Access-Control-Allow-Origin: * (RFC 7033)
    • Create dynamically registered clients through application_model so custom models work with DCR
  • #351 Align OpenID Connect token/authorization responses with Doorkeeper's response contract: return the plaintext access token from the id_token token implicit response (fixes hash_token_secrets), define #issued_token on OIDC responses, and attach the ID token before after_successful_strategy_response fires
  • #353 Enrich Doorkeeper 6.0's RFC 8414 metadata document (/.well-known/oauth-authorization-server) with the OpenID Connect fields (jwks_uri, userinfo_endpoint, signing algs, claims) via the custom_metadata seam; app-configured custom_metadata keeps precedence. No behavior change on Doorkeeper < 6.0
  • #355 Compute at_hash from the plaintext access token instead of the stored value, fixing ID Token validation when hash_token_secrets is enabled
  • #360 Load the OpenID Connect constants with autoload instead of require, including the requests and responses this gem contributes to Doorkeeper's own namespace. No public constant changes name or moves (#362)
  • #363 Extend #349's id_token guard to the password grant with skip_client_authentication_for_password_grant ? previously returned an unhandled 500
  • #370 Correct the stale rake db:migrate command to rails db:migrate in the README, the #243 migration note, and the post_logout_redirect_uris missing-column error message
  • #372 Fix duplicate entries in the discovery document's claims_supported when a custom claim shadows a base claim (iss/sub/aud/exp/iat)
  • #373 Fix prompt=consent under Doorkeeper's api_only mode ? the consent step now returns the pre-authorization as JSON instead of attempting to render a template that ActionController::API cannot serve
  • #381 Echo the registered client_name in the Dynamic Client Registration response, as RFC 7591 ?3.2.1 requires the response to include all registered client metadata
Changelog

Sourced from doorkeeper-openid_connect's changelog.

v2.0.0 (2026-09-22)

[!IMPORTANT]

  • Breaking (class overrides): a configured id_token_class / user_info_class must now inherit from Doorkeeper::OpenidConnect::IdToken / UserInfo (#364)
  • Breaking (settings removed): the deprecated jws_private_key / jws_public_key initializer settings are gone (#387)
  • Breaking (constant renamed): Doorkeeper::OpenidConnect::HybridIdTokenConcern is now AtHashConcern, with no alias for the old name (#399)

Coming from 1.10.x? Every breaking change listed under 2.0.0.beta1 below applies as well ? the post_logout_redirect_uris migration (#243), the id_token token response type change (#337), the removal of IdTokenToken (#338) and the Dynamic Client Registration defaults (#350). Those notes name HybridIdTokenConcern; read them as AtHashConcern, which is what 2.0.0 ships.

Migration from Old Versions walks through each one.

  • Security: Register a dynamically registered client with the server's default_scopes when the registration request omits scope, instead of persisting an empty scope set. Only deployments that enable dynamic_client_registration are affected.
  • #364 Breaking: Require id_token_class / user_info_class overrides to inherit from Doorkeeper::OpenidConnect::IdToken / UserInfo (#344). Adds an IdToken#select_key hook returning the signing key and its algorithm together (IdToken::SigningKey) for per-client, rotating or multi-tenant keys, and binds the at_hash digest to that algorithm (OIDC Core ?3.2.2.10) rather than the global signing_algorithm
  • #387 Breaking: Remove the deprecated jws_private_key and jws_public_key initializer settings
  • #399 Breaking: Rename Doorkeeper::OpenidConnect::HybridIdTokenConcern to AtHashConcern. The old name described the id_token token response type as a hybrid flow, but OpenID Connect Core defines that response type under the Implicit Flow (?3.2) ? the Hybrid Flow response types of ?3.3 are not implemented by this gem. Removed without an alias: the constant only ever shipped in 2.0.0.beta1

v2.0.0.beta1 (2026-08-20)

[!IMPORTANT]

  • This is a prerelease. RubyGems does not resolve prereleases from an unqualified requirement, so it must be requested explicitly: gem "doorkeeper-openid_connect", "2.0.0.beta1"
  • Migration required: existing installations must add the post_logout_redirect_uris column ? rails generate doorkeeper:openid_connect:add_post_logout_redirect_uris followed by rails db:migrate (#243)
  • Breaking (hybrid response type): the id_token token response object is now the configured id_token_class extended with HybridIdTokenConcern, and a custom id_token_class must expose an #access_token reader (#337)
  • Breaking (constant removed): Doorkeeper::OpenidConnect::IdTokenToken is gone ? custom subclasses must subclass IdToken and include HybridIdTokenConcern (#338)
  • Breaking (Dynamic Client Registration): a registration request that omits response_types / grant_types now defaults to ["code"] / ["authorization_code"] per RFC 7591 ?2, instead of inheriting the server's global configuration (#350)

Migration from Old Versions walks through each one.

  • #243 Add per-client post_logout_redirect_uris for RP-Initiated Logout, exposed via Doorkeeper::Application#post_logout_redirect_uris and #valid_post_logout_redirect_uri?(uri). URIs are validated with the same rules as redirect_uri; Dynamic Client Registration accepts and echoes them back
  • #320 Support mounting the engine under multiple named scopes ? use_doorkeeper_openid_connect as: :users makes each mount's discovery document advertise its own endpoints (#192)
  • #322 Fall back to Doorkeeper's issuer configuration when the OpenID Connect issuer is not set. The OpenID Connect value still takes precedence (#321)
  • #323 Resolve token_endpoint_auth_methods_supported from Doorkeeper's client authentication methods registry when available, falling back to legacy client_credentials_methods on older versions
  • #332 Fix grant_types_supported listing refresh_token twice when enabled via both grant_flows and use_refresh_token
  • #333 Emit the RFC 9207 iss parameter on id_token / id_token token authorization responses and on OIDC error redirects, and advertise authorization_response_iss_parameter_supported in the discovery document. No behavior change until Doorkeeper is configured with an issuer
  • #334 Allow Doorkeeper 6.0 (>= 5.5, < 7.0). Note: Doorkeeper 6.0's force_pkce applies to confidential clients too ? id_token / id_token token authorization requests are rejected unless they carry a code_challenge
  • #335 Add id_token_class and user_info_class config options for custom ID Token / UserInfo response objects
  • #337 Rework id_token_class / user_info_class internals ? lazy-resolve and validate configured classes at first use (fixes zeitwerk on Rails 7+) ? and deprecate Doorkeeper::OpenidConnect::IdTokenToken. A custom id_token_class must now expose an #access_token reader. Breaking (type change): the hybrid response token is now the configured id_token_class extended with HybridIdTokenConcern ? see the migration guide
  • #338 Breaking: Remove the deprecated IdTokenToken class. Custom subclasses must subclass IdToken and include HybridIdTokenConcern instead
  • #341 Fix dynamic client registration to respect the application_class configuration
  • #347 Omit symmetric (oct) keys from the JWKS endpoint when signing with an HMAC algorithm (RFC 7517)
  • #348 Authorization endpoint hardening:
    • Treat a malformed max_age parameter (e.g. max_age[]=1) as absent instead of a 500
    • Build prompt=login / prompt=select_account return URLs without mutating the shared request.query_parameters hash
    • Route internal errors (e.g. InvalidConfiguration) to a 500 instead of leaking them as authorization error redirects
  • #349 Fix several 500 errors in the claims pipeline: gracefully omit id_token when the access token has no resource owner, no application, or an owner that no longer resolves; return 401 invalid_token at userinfo for the same cases. Also dispatch claims whose response: option is configured with strings (e.g. response: ["id_token"]), which were previously dropped from every response
  • #350 Discovery / Dynamic Client Registration spec compliance:
    • Advertise the standard implicit grant type instead of the internal implicit_oidc name (RFC 7591 ?2)
    • Breaking: omitted response_types / grant_types in a registration request now default to ["code"] / ["authorization_code"] per RFC 7591 ?2
    • Use RFC 7591 ?3.2.2 error codes (invalid_redirect_uri / invalid_client_metadata) instead of the invented invalid_client_params

... (truncated)

Commits
  • bd1d3e9 [ci skip] Fix CHANGELOG
  • 31213cc Merge pull request #400 from doorkeeper-gem/release/2.0.0
  • 7e1e2cd Merge pull request #403 from doorkeeper-gem/chore/pin-json-below-3
  • ad6ac58 Pin the development dependency on json below 3.0
  • 4e514f0 Merge pull request #397 from doorkeeper-gem/chore/rubocop-todo-delete
  • 04dcdd5 Merge pull request #399 from 55728/chore/rename-at-hash-concern
  • ab9f75e Merge pull request #396 from doorkeeper-gem/chore/rubocop-todo-drop-metrics
  • 341f862 Merge pull request #395 from doorkeeper-gem/chore/rubocop-metrics-refactors
  • 21395bc Release 2.0.0 :tada:
  • 4c55b37 Rename HybridIdTokenConcern to AtHashConcern
  • Additional commits viewable in compare view

Updates `dalli` from 5.1.0 to 5.1.1
Release notes

Sourced from dalli's releases.

v5.1.1

Security release. Fixes GHSA-6wmv-xq9m-fmp7, a memcached command injection through numeric arguments. Upgrading is recommended.

Security:

  • Fix memcached command injection through numeric arguments (GHSA-6wmv-xq9m-fmp7)
    • The default argument of incr/decr, and fetch_with_lock's lock_ttl and recache_threshold, were written into the meta protocol command without conversion, so a String containing CRLF injected additional memcached commands (e.g. set, flush_all) on the connection
    • These arguments must now be Integers, or Strings of decimal digits; anything else raises ArgumentError before a request is sent
    • As defense in depth, RequestFormatter now converts every numeric flag it writes (D, J, N, R, T) to an Integer
    • Affects 3.2.0 and later (3.2.x only with protocol: :meta); fixed in 5.1.1 and 4.3.4
    • Thanks to oss-security-shop for the report

Performance:

  • Reduce Ruby overhead on the single-key get path by about 28% (#1160)
    • A plain get builds its mg request with one string interpolation instead of going through meta_get's keyword arguments, and skips option handling when called without options
    • A VA <size> f<flags> hit line is parsed in place instead of being split into tokens
    • The key check for control characters and whitespace uses a byte class that matches the same ASCII bytes as [\p{Cntrl}\s], about 5x faster; this applies to every operation that sends a key
    • Allocations per get hit drop from 23 to 16
    • Thanks to Julian Richard Contreras for this contribution
  • Speed up multi-server get_multi by about 30% (4 servers, 100 keys), and bring small batches in line with 2.7.11 (#1161)
    • Each server's queries and terminating noop are sent before the next server's are built, so memcached answers earlier servers while later ones are prepared
    • A server's queries are built in one pass with RequestFormatter.multi_meta_get, and plain get_multi no longer requests the CAS value it discards (get_multi_cas still does)
    • Pipelined replies are parsed in one pass over the returned flags
    • Routing many keys checks each server's alive? once per call instead of twice per key, and the ring's binary search runs over plain integers
    • Thanks to Julian Richard Contreras for this contribution

Development:

  • Fix offenses reported by RuboCop 1.91 and require rubocop >= 1.91 (#1162)
    • RuboCop 1.91 adds Style/DirectiveScope; single-statement disable/enable pairs become disable-next directives, which older RuboCop versions do not recognize
    • Removes a misplaced # encoding: ascii comment in client.rb that Ruby had always ignored
Changelog

Sourced from dalli's changelog.

5.1.1

Security:

  • Fix memcached command injection through numeric arguments (GHSA-6wmv-xq9m-fmp7)
    • The default argument of incr/decr, and fetch_with_lock's lock_ttl and recache_threshold, were written into the meta protocol command without conversion, so a String containing CRLF injected additional memcached commands (e.g. set, flush_all) on the connection
    • These arguments must now be Integers, or Strings of decimal digits; anything else raises ArgumentError before a request is sent
    • As defense in depth, RequestFormatter now converts every numeric flag it writes (D, J, N, R, T) to an Integer
    • Affects 3.2.0 and later (3.2.x only with protocol: :meta); fixed in 5.1.1 and 4.3.4
    • Thanks to oss-security-shop for the report

Performance:

  • Reduce Ruby overhead on the single-key get path by about 28% (#1160)
    • A plain get builds its mg request with one string interpolation instead of going through meta_get's keyword arguments, and skips option handling when called without options
    • A VA <size> f<flags> hit line is parsed in place instead of being split into tokens
    • The key check for control characters and whitespace uses a byte class that matches the same ASCII bytes as [\p{Cntrl}\s], about 5x faster; this applies to every operation that sends a key
    • Allocations per get hit drop from 23 to 16
    • Thanks to Julian Richard Contreras for this contribution
  • Speed up multi-server get_multi by about 30% (4 servers, 100 keys), and bring small batches in line with 2.7.11 (#1161)
    • Each server's queries and terminating noop are sent before the next server's are built, so memcached answers earlier servers while later ones are prepared
    • A server's queries are built in one pass with RequestFormatter.multi_meta_get, and plain get_multi no longer requests the CAS value it discards (get_multi_cas still does)
    • Pipelined replies are parsed in one pass over the returned flags
    • Routing many keys checks each server's alive? once per call instead of twice per key, and the ring's binary search runs over plain integers
    • Thanks to Julian Richard Contreras for this contribution

Development:

  • Fix offenses reported by RuboCop 1.91 and require rubocop >= 1.91 (#1162)
    • RuboCop 1.91 adds Style/DirectiveScope; single-statement disable/enable pairs become disable-next directives, which older RuboCop versions do not recognize
    • Removes a misplaced # encoding: ascii comment in client.rb that Ruby had always ignored
Commits
  • 7bd7daf Merge commit from fork
  • e3b73f6 Prepare 5.1.1 release
  • 5d6b470 Reject non-integer numeric flags in meta protocol commands
  • 473932d Merge pull request #1163 from petergoldstein/docs/changelog-1160-1161-1162
  • 4c20d0c Update CHANGELOG for #1160, #1161 and #1162
  • a2dac30 Merge pull request #1161 from radixdev/perf/faster-multi-server-get-multi
  • dd81192 Add PR number to changelog entry
  • 7b974e5 Speed up multi-server get_multi
  • 3c6e9c6 Merge pull request #1160 from radixdev/perf/faster-single-get
  • 758d1b9 Treat false options like nil on the get fast path
  • Additional commits viewable in compare view

Updates `aws-sdk-s3` from 1.232.1 to 1.232.2
Changelog

Sourced from aws-sdk-s3's changelog.

1.232.2 (2026-09-25)

  • Issue - Ensure the internally-created executor is shutdown on error in TransferManager and Aws::S3::Object resource methods, preventing leaked worker threads on multipart transfer failures (#3419).
Commits

Updates `herb` from 0.10.4 to 0.11.0
Release notes

Sourced from herb's releases.

v0.11.0

Herb v0.11

Herb v0.11 ships alongside ReActionView v0.6. Check out the "What's new in Herb v0.11" post on the Herb Blog.

Parser

  • Introduce ERBIterationBlockNode and iteration_nodes option by @?marcoroth in marcoroth/herb#1912
  • Introduce HerbDirectiveNode and HerbStateDirectiveNode by @?marcoroth in marcoroth/herb#2435
  • Introduce ERBCommentNode by @?marcoroth in marcoroth/herb#2605
  • Introduce XMLProcessingInstructionNode by @?marcoroth in marcoroth/herb#2266
  • Add an erb_openers option for custom ERB tag openers by @?marcoroth in #2487, #2491 and #2645
  • Follow HTML5 tokenizer for attribute names/values and comments by @?marcoroth in marcoroth/herb#2593
  • Treat every raw text element, including <textarea>, as raw text by @?marcoroth in #2596 and #2601
  • Treat <title> content as text by @?marcoroth in marcoroth/herb#2597
  • Key foreign content on a kind and the element name by @?marcoroth in marcoroth/herb#2598
  • Count characters, not bytes, when computing columns by @?marcoroth in marcoroth/herb#2442
  • Convert dynamic boolean attributes to conditional attributes by @?marcoroth in marcoroth/herb#2112
  • Convert literals to static text in transform_conditionals by @?marcoroth in marcoroth/herb#2302
  • Don't transform locals that shadow Action View helpers by @?marcoroth in #1900 and #2076
  • Only analyze receiver-less render calls as Action View renders by @?marcoroth in m... _Description has been truncated_ You can view, comment on, or merge this pull request online at: https://github.com/openstreetmap/openstreetmap-website/pull/7450 -- Commit Summary -- * Bump the dependencies group across 1 directory with 12 updates -- File Changes -- M Gemfile.lock (26) -- Patch Links -- https://github.com/openstreetmap/openstreetmap-website/pull/7450.patch https://github.com/openstreetmap/openstreetmap-website/pull/7450.diff -- Reply to this email directly or view it on GitHub: https://github.com/openstreetmap/openstreetmap-website/pull/7450 You are receiving this because you are subscribed to this thread. Message ID: -------------- next part -------------- An HTML attachment was scrubbed... URL: From notifications at github.com Thu Oct 1 10:19:56 2026 From: notifications at github.com (Tom Hughes) Date: Thu, 01 Oct 2026 03:19:56 -0700 Subject: [openstreetmap/openstreetmap-website] Bump rails from 8.1.3.1 to 8.1.4 in the rails group across 1 directory (PR #7444) In-Reply-To: References: Message-ID: tomhughes left a comment (openstreetmap/openstreetmap-website#7444) @dependabot rebase -- Reply to this email directly or view it on GitHub: https://github.com/openstreetmap/openstreetmap-website/pull/7444#issuecomment-5929395456 You are receiving this because you are subscribed to this thread. Message ID: -------------- next part -------------- An HTML attachment was scrubbed... URL: From notifications at github.com Thu Oct 1 10:20:57 2026 From: notifications at github.com (dependabot[bot]) Date: Thu, 01 Oct 2026 03:20:57 -0700 Subject: [openstreetmap/openstreetmap-website] Bump rails from 8.1.3.1 to 8.1.4 in the rails group across 1 directory (PR #7444) In-Reply-To: References: Message-ID: @dependabot[bot] pushed 1 commit. d762b61b31c018f5ddd8f7d036d21160d0659930 Bump rails from 8.1.3.1 to 8.1.4 in the rails group across 1 directory -- View it on GitHub: https://github.com/openstreetmap/openstreetmap-website/pull/7444/changes/45c53d910d7337fc635f9760b34d7dcb94fa0db1..d762b61b31c018f5ddd8f7d036d21160d0659930 You are receiving this because you are subscribed to this thread. Message ID: -------------- next part -------------- An HTML attachment was scrubbed... URL: From notifications at github.com Thu Oct 1 10:21:03 2026 From: notifications at github.com (Pablo Brasero) Date: Thu, 01 Oct 2026 03:21:03 -0700 Subject: [openstreetmap/openstreetmap-website] Moderation zones: add layer selector in form (Issue #7451) Message-ID: pablobm created an issue (openstreetmap/openstreetmap-website#7451) This was requested by a member of the DWG. When creating a moderation zone, the form shows a map with the Standard/Carto layer. This can make it tricky to find places with foreign names, particularly when rendered in a foreign script. Eg: try finding Chongqing in China, or Nay Pyi Taw in Myanmar, without knowledge of the corresponding languages/scripts. The solution proposed by the member of the DWG would be to show a layer selector next to the map. Here they would be able to select the MapTiler OMT layer when appropriate, as it renders names in the language of the website. When I first built the moderation zones form I planned to include this, but ended up dropping it for simplicity. Here's a commit that may save some time to anyone attempting this in the future: https://github.com/openstreetmap/openstreetmap-website/commit/2584fdc7fd3d4d96810f6140d5fb86d2f5cf35c8 -- Reply to this email directly or view it on GitHub: https://github.com/openstreetmap/openstreetmap-website/issues/7451 You are receiving this because you are subscribed to this thread. Message ID: -------------- next part -------------- An HTML attachment was scrubbed... URL: From notifications at github.com Thu Oct 1 10:38:51 2026 From: notifications at github.com (Tom Hughes) Date: Thu, 01 Oct 2026 03:38:51 -0700 Subject: [openstreetmap/openstreetmap-website] Bump rails from 8.1.3.1 to 8.1.4 in the rails group across 1 directory (PR #7444) In-Reply-To: References: Message-ID: tomhughes left a comment (openstreetmap/openstreetmap-website#7444) @dependabot rebase -- Reply to this email directly or view it on GitHub: https://github.com/openstreetmap/openstreetmap-website/pull/7444#issuecomment-5929665583 You are receiving this because you are subscribed to this thread. Message ID: -------------- next part -------------- An HTML attachment was scrubbed... URL: From notifications at github.com Thu Oct 1 10:40:02 2026 From: notifications at github.com (dependabot[bot]) Date: Thu, 01 Oct 2026 03:40:02 -0700 Subject: [openstreetmap/openstreetmap-website] Bump rails from 8.1.3.1 to 8.1.4 in the rails group across 1 directory (PR #7444) In-Reply-To: References: Message-ID: @dependabot[bot] pushed 1 commit. 356b3530ebcfe3b5c00715af54bce475b182fcc1 Bump rails from 8.1.3.1 to 8.1.4 in the rails group across 1 directory -- View it on GitHub: https://github.com/openstreetmap/openstreetmap-website/pull/7444/changes/d762b61b31c018f5ddd8f7d036d21160d0659930..356b3530ebcfe3b5c00715af54bce475b182fcc1 You are receiving this because you are subscribed to this thread. Message ID: -------------- next part -------------- An HTML attachment was scrubbed... URL: From notifications at github.com Thu Oct 1 10:46:42 2026 From: notifications at github.com (dependabot[bot]) Date: Thu, 01 Oct 2026 03:46:42 -0700 Subject: [openstreetmap/openstreetmap-website] Bump the dependencies group across 1 directory with 12 updates (PR #7450) In-Reply-To: References: Message-ID: Closed #7450. -- Reply to this email directly or view it on GitHub: https://github.com/openstreetmap/openstreetmap-website/pull/7450#event-32243769806 You are receiving this because you are subscribed to this thread. Message ID: -------------- next part -------------- An HTML attachment was scrubbed... URL: From notifications at github.com Thu Oct 1 10:46:42 2026 From: notifications at github.com (dependabot[bot]) Date: Thu, 01 Oct 2026 03:46:42 -0700 Subject: [openstreetmap/openstreetmap-website] Bump the dependencies group across 1 directory with 12 updates (PR #7450) In-Reply-To: References: Message-ID: dependabot[bot] left a comment (openstreetmap/openstreetmap-website#7450) Looks like these dependencies are updatable in another way, so this is no longer needed. -- Reply to this email directly or view it on GitHub: https://github.com/openstreetmap/openstreetmap-website/pull/7450#issuecomment-5929773264 You are receiving this because you are subscribed to this thread. Message ID: -------------- next part -------------- An HTML attachment was scrubbed... URL: From notifications at github.com Thu Oct 1 10:47:05 2026 From: notifications at github.com (dependabot[bot]) Date: Thu, 01 Oct 2026 03:47:05 -0700 Subject: [openstreetmap/openstreetmap-website] Bump the dependencies group across 1 directory with 11 updates (PR #7452) Message-ID: Bumps the dependencies group with 11 updates in the / directory: | Package | From | To | | --- | --- | --- | | [activerecord-postgis](https://github.com/seuros/activerecord-postgis) | `0.6.0` | `0.6.1` | | [actionpack-page_caching](https://github.com/rails/actionpack-page_caching) | `1.2.4` | `1.2.5` | | [doorkeeper](https://github.com/doorkeeper-gem/doorkeeper) | `5.9.7` | `5.9.9` | | [doorkeeper-openid_connect](https://github.com/doorkeeper-gem/doorkeeper-openid_connect) | `1.10.5` | `2.0.0` | | [dalli](https://github.com/petergoldstein/dalli) | `5.1.0` | `5.1.1` | | [aws-sdk-s3](https://github.com/aws/aws-sdk-ruby) | `1.232.1` | `1.232.2` | | [herb](https://github.com/marcoroth/herb) | `0.10.4` | `0.11.0` | | [database_consistency](https://github.com/djezzzl/database_consistency) | `3.0.12` | `3.0.13` | | [aws-partitions](https://github.com/aws/aws-sdk-ruby) | `1.1289.0` | `1.1291.0` | | [bindata](https://github.com/dmendel/bindata) | `3.0.0` | `3.0.1` | | [rdoc](https://github.com/ruby/rdoc) | `8.0.0` | `8.1.0` | Updates `activerecord-postgis` from 0.6.0 to 0.6.1
    Release notes

    Sourced from activerecord-postgis's releases.

    activerecord-postgis: v0.6.1

    0.6.1 (2026-09-22)

    Bug Fixes

    • don't memoize RGeo factory in spatial types (#20) (d9e9f08)
    Changelog

    Sourced from activerecord-postgis's changelog.

    0.6.1 (2026-09-22)

    Bug Fixes

    • don't memoize RGeo factory in spatial types (#20) (d9e9f08)
    Commits

    Updates `actionpack-page_caching` from 1.2.4 to 1.2.5
    Changelog

    Sourced from actionpack-page_caching's changelog.

    1.2.5 (September 21, 2026)

    • Fix directory check for directory with shared prefix

    John Hawthorn

    Commits

    Updates `doorkeeper` from 5.9.7 to 5.9.9
    Release notes

    Sourced from doorkeeper's releases.

    v5.9.9

    • Fix: AuthorizedApplicationsController now answers 401 Unauthorized instead of running with a nil resource owner, which listed and revoked every token that has no resource owner ? the ones the client credentials flow issues. Affected host applications are those whose resource_owner_authenticator answers nil without halting the request itself; the generated initializer's example redirects and is not affected.
    • Fix: AuthorizationsController#destroy now validates the client and redirect URI before producing the deny response, and renders ? never redirects ? when validation fails. Previously the deny path performed no OAuth-layer validation at all, allowing an open redirect to an attacker-controlled origin with the OAuth state attached. Also reject unregistered response_type values on the authorization endpoint rather than resolving them through the constantize fallback.
    • Fix: refuse redirect URIs with a script scheme (javascript, vbscript, data) both when an application is registered and at authorization time, regardless of forbid_redirect_uri. Such a URI is never a legitimate redirection endpoint, and with response_mode=form_post it became the action of the auto-submitting form the authorization server renders on its own origin. Already stored records with such a URI are now refused with invalid_redirect_uri before the consent screen is shown.
    • #1938 Fix: a request body ActionDispatch cannot parse (malformed JSON under a JSON content type, say) no longer raises ActionDispatch::Http::Parameters::ParseError out of Doorkeeper::OAuth::Token.from_request and doorkeeper_token. Since 5.9.7 the RFC 6750 ?2 multi-method check read the body on every request, so such a request raised even when it carried a valid Bearer header. The body is now treated as carrying no token, the same way ActionDispatch's own #filtered_parameters treats that error.
    Changelog

    Sourced from doorkeeper's changelog.

    Changelog

    See https://github.com/doorkeeper-gem/doorkeeper/wiki/Migration-from-old-versions for upgrade guides.

    User-visible changes worth mentioning.

    main

    • [#PR ID] Description of the change.
    • #1960 Ignore the port of http://localhost redirect URIs like that of loopback IP literals (RFC 8252 ?7.3 / ?8.3).
    • #1959 A custom access_token_generator now receives the token's resource (RFC 8707), so a JWT generator can set aud.

    6.0.0.rc2

    Please make sure you read the Upgrade guides and changelog below before the update since this version includes breaking changes.

    • #1951 Fix: the built gem no longer contains vendor/bundle. The gemspec globed all of vendor/, which swept in the bundle installed by the release workflow; 6.0.0.rc1 is a 44.4 MB download against 154 KB for 6.0.0.beta2.
    • Fix: AuthorizedApplicationsController now answers 401 Unauthorized instead of running with a nil resource owner, which listed and revoked every token that has no resource owner ? the ones the client credentials flow issues. Affected host applications are those whose resource_owner_authenticator answers nil without halting the request itself; the generated initializer's example redirects and is not affected.
    • Fix: AuthorizationsController#destroy now validates the client and redirect URI before producing the deny response, and renders ? never redirects ? when validation fails. Previously the deny path performed no OAuth-layer validation at all, allowing an open redirect to an attacker-controlled origin with the OAuth state attached. Also reject unregistered response_type values on the authorization endpoint rather than resolving them through the constantize fallback.
    • Fix: refuse redirect URIs with a script scheme (javascript, vbscript, data) both when an application is registered and at authorization time, regardless of forbid_redirect_uri. Such a URI is never a legitimate redirection endpoint, and with response_mode=form_post it became the action of the auto-submitting form the authorization server renders on its own origin. Already stored records with such a URI are now refused with invalid_redirect_uri before the consent screen is shown.
    • #1932 Fix: keep the scope originally granted by the resource owner on refresh tokens (RFC 6749 ?6), so a chain narrowed on one refresh can return to its granted scope. Tracked in a new refresh_token_scopes column; existing installations opt in with rails generate doorkeeper:refresh_token_scopes.
    • #1933 Warn at boot when the implicit or password grant flow is enabled: both are deprecated by RFC 9700 (OAuth 2.0 Security BCP) and removed from OAuth 2.1, and may be removed in a future Doorkeeper release.
    • #1915 Fix: fetching a client's jwks_uri now falls back to the other addresses returned by DNS when the first one cannot be connected to.
    • #1934 The refresh_token grant now consults custom_access_token_expires_in (with Doorkeeper::OAuth::REFRESH_TOKEN as the context grant type) for the TTL of the refreshed access token. A callable that returns nil for this grant, or no callable at all, keeps inheriting the TTL of the token being refreshed as before. A callable that returns a value unconditionally now applies to refreshes as well.
    • #1935 Add opt-in public_client_access_token_expires_in configuration option: a ceiling for the lifetime of access tokens issued to public (non-confidential) clients by any grant, refresh_token included, as OAuth 2.1 Section 2.4 requires the exposure of tokens issued to unauthenticated clients to be limited. Confidential clients are not affected.
    • #1938 Fix: a request body ActionDispatch cannot parse (malformed JSON under a JSON content type, say) no longer raises ActionDispatch::Http::Parameters::ParseError out of Doorkeeper::OAuth::Token.from_request and doorkeeper_token. Since 5.9.7 the RFC 6750 ?2 multi-method check read the body on every request, so such a request raised even when it carried a valid Bearer header. The body is now treated as carrying no token, the same way ActionDispatch's own #filtered_parameters treats that error.
    • #1950 Document hash_token_secrets / hash_application_secrets fallback: as a migration-period setting that should be removed once every row is hashed, and warn at boot for as long as one is configured. While a :plain fallback is active the stored value is itself a valid credential, so those columns need protecting as carefully as plaintext ones.
    • #1953 Fix: public_client_access_token_expires_in now also holds under reuse_access_token and with String TTLs, and the refresh_token grant hands custom_access_token_expires_in and resource_indicator_validator what every other grant does.

    6.0.0.rc1

    Please make sure you read the Upgrade guides and changelog below before the update since this version includes breaking changes.

    • Require Ruby >= 3.2 in the gemspec, matching the CI matrix (3.2 / 3.3 / 3.4 / 4.0). Ruby 2.7, 3.0 and 3.1 have reached end-of-life.
    • Fix: the client_secret_basic strategy now requires a client_id sent in the request body to name the same client as the Authorization: Basic header ? the RFC 7521 ?4.2 agreement check private_key_jwt already applies to an assertion's issuer. A request presenting Basic credentials for one client and a client_id for another was authenticated as the Basic client, silently discarding the other identity. A bare client_id is not a client authentication method of its own, so the RFC 6749 ?2.3 multiple-methods check does not (and should not) count it.
    • #1906 Internal: exempt Doorkeeper::Config from Metrics/ClassLength with a directive on the class itself instead of raising the cop's global ceiling, so adding a configuration option no longer trips the limit.
    • #1907 Fix: a resource parameter no longer produces a 500 at the authorization endpoint when resource_indicator_validator is configured without the doorkeeper:resource_indicators migration. Such a request is now answered with server_error, as the token endpoint already did, and the missing migration is warned about at boot.
    • #1909 Add Rails 8.1 to CI test matrix.
    • #1910 Add opt-in validate_client_before_resource_owner_authentication configuration option: the authorization endpoint validates client_id and redirect_uri before authenticating the resource owner, so users are not sent through login for a request that can only fail.
    • #1916 Fix broken Coveralls coverage reporting.
    • #1918 The api_only controller specs no longer load the real controller sources, which detached the coverage of every other example that ran them and made the reported coverage depend on the random example order.
    • #1923 Fix: the fallback secret upgrade no longer writes the matched secret back over a value stored in the meantime, which could undo a concurrent #renew_secret and leave the superseded secret valid. Active Record writes the upgrade conditionally on the column still holding the value that matched; other ORMs can implement the new write_upgraded_secret hook. The Active Record write is a single update_all statement, so model callbacks and validations no longer run on this upgrade (timestamps and optimistic locking are still maintained).
    • #1925 Internal: pin the development dependency on json below 3.0. json 3 removed the positional options Hash from JSON.parse and the quirks_mode option from JSON.generate, both of which Active Support still uses, so the suite could not run on any released Rails version.
    • #1926 [BREAKING] Fix: private_key_jwt client authentication no longer accepts an audience derived from the request's Host header, which let a client assertion minted for another authorization server be replayed here. A server that configures neither issuer nor Rails' default_url_options[:host] now has no acceptable audience and refuses every assertion, and is warned about it at boot.
    • [BREAKING] Refuse requests that transmit the access token by more than one method (RFC 6750 ?2) with an invalid_request error, instead of silently authorizing with the first method that yielded a token and discarding the rest. The form-encoded body (?2.2) and the URI query (?2.3) count as two methods even though Rails and Rack merge them into a single params hash, and the same token repeated across two methods is refused too ? ?2 forbids the second method, not a disagreement between the two.
      • Only the built-in extraction methods take part in the check; a custom callable in access_token_methods keeps the historical first-wins behavior and is never invoked more than once.
      • Doorkeeper::OAuth::Token.from_request / .authenticate raise Doorkeeper::Errors::MultipleAccessTokenMethods. Doorkeeper.authenticate and every doorkeeper_token helper (Rails, Grape, and Doorkeeper's own controllers) keep their token-or-nil contract, so doorkeeper_authorize! renders the refusal through a new doorkeeper_bad_request_render_options(error:) hook (head 400 unless you override it).

    ... (truncated)

    Commits
    • 6f65d41 Backport gemspec to avoid vendor/bundle
    • 1879ce4 Release 5.9.9 :tada:
    • 9403233 Merge commit from fork
    • 6d711eb Merge commit from fork
    • 7504992 Refuse redirect URIs with a script scheme
    • de57e75 Merge commit from fork
    • 0960bd7 Merge back release workflow for 5.9 branch
    • 9cafb36 Validate the client and redirect URI on the authorization deny path
    • f6ec046 Refuse authorized applications requests with no resource owner
    • e72e53f Merge pull request #1939 from doorkeeper-gem/chore/bump-5.9.8
    • Additional commits viewable in compare view

    Updates `doorkeeper-openid_connect` from 1.10.5 to 2.0.0
    Release notes

    Sourced from doorkeeper-openid_connect's releases.

    v2.0.0

    • Security: Register a dynamically registered client with the server's default_scopes when the registration request omits scope, instead of persisting an empty scope set. Only deployments that enable dynamic_client_registration are affected.
    • #364 Breaking: Require id_token_class / user_info_class overrides to inherit from Doorkeeper::OpenidConnect::IdToken / UserInfo (#344). Adds an IdToken#select_key hook returning the signing key and its algorithm together (IdToken::SigningKey) for per-client, rotating or multi-tenant keys, and binds the at_hash digest to that algorithm (OIDC Core ?3.2.2.10) rather than the global signing_algorithm
    • #387 Breaking: Remove the deprecated jws_private_key and jws_public_key initializer settings
    • #399 Breaking: Rename Doorkeeper::OpenidConnect::HybridIdTokenConcern to AtHashConcern. The old name described the id_token token response type as a hybrid flow, but OpenID Connect Core defines that response type under the Implicit Flow (?3.2) ? the Hybrid Flow response types of ?3.3 are not implemented by this gem. Removed without an alias: the constant only ever shipped in 2.0.0.beta1

    v2.0.0.beta1

    [!IMPORTANT]

    • This is a prerelease. RubyGems does not resolve prereleases from an unqualified requirement, so it must be requested explicitly: gem "doorkeeper-openid_connect", "2.0.0.beta1"
    • Migration required: existing installations must add the post_logout_redirect_uris column ? rails generate doorkeeper:openid_connect:add_post_logout_redirect_uris followed by rails db:migrate (#243)
    • Breaking (hybrid response type): the id_token token response object is now the configured id_token_class extended with HybridIdTokenConcern, and a custom id_token_class must expose an #access_token reader (#337)
    • Breaking (constant removed): Doorkeeper::OpenidConnect::IdTokenToken is gone ? custom subclasses must subclass IdToken and include HybridIdTokenConcern (#338)
    • Breaking (Dynamic Client Registration): a registration request that omits response_types / grant_types now defaults to ["code"] / ["authorization_code"] per RFC 7591 ?2, instead of inheriting the server's global configuration (#350)

    Migration from Old Versions walks through each one.

    • #243 Add per-client post_logout_redirect_uris for RP-Initiated Logout, exposed via Doorkeeper::Application#post_logout_redirect_uris and #valid_post_logout_redirect_uri?(uri). URIs are validated with the same rules as redirect_uri; Dynamic Client Registration accepts and echoes them back
    • #320 Support mounting the engine under multiple named scopes ? use_doorkeeper_openid_connect as: :users makes each mount's discovery document advertise its own endpoints (#192)
    • #322 Fall back to Doorkeeper's issuer configuration when the OpenID Connect issuer is not set. The OpenID Connect value still takes precedence (#321)
    • #323 Resolve token_endpoint_auth_methods_supported from Doorkeeper's client authentication methods registry when available, falling back to legacy client_credentials_methods on older versions
    • #332 Fix grant_types_supported listing refresh_token twice when enabled via both grant_flows and use_refresh_token
    • #333 Emit the RFC 9207 iss parameter on id_token / id_token token authorization responses and on OIDC error redirects, and advertise authorization_response_iss_parameter_supported in the discovery document. No behavior change until Doorkeeper is configured with an issuer
    • #334 Allow Doorkeeper 6.0 (>= 5.5, < 7.0). Note: Doorkeeper 6.0's force_pkce applies to confidential clients too ? id_token / id_token token authorization requests are rejected unless they carry a code_challenge
    • #335 Add id_token_class and user_info_class config options for custom ID Token / UserInfo response objects
    • #337 Rework id_token_class / user_info_class internals ? lazy-resolve and validate configured classes at first use (fixes zeitwerk on Rails 7+) ? and deprecate Doorkeeper::OpenidConnect::IdTokenToken. A custom id_token_class must now expose an #access_token reader. Breaking (type change): the hybrid response token is now the configured id_token_class extended with HybridIdTokenConcern ? see the migration guide
    • #338 Breaking: Remove the deprecated IdTokenToken class. Custom subclasses must subclass IdToken and include HybridIdTokenConcern instead
    • #341 Fix dynamic client registration to respect the application_class configuration
    • #347 Omit symmetric (oct) keys from the JWKS endpoint when signing with an HMAC algorithm (RFC 7517)
    • #348 Authorization endpoint hardening:
      • Treat a malformed max_age parameter (e.g. max_age[]=1) as absent instead of a 500
      • Build prompt=login / prompt=select_account return URLs without mutating the shared request.query_parameters hash
      • Route internal errors (e.g. InvalidConfiguration) to a 500 instead of leaking them as authorization error redirects
    • #349 Fix several 500 errors in the claims pipeline: gracefully omit id_token when the access token has no resource owner, no application, or an owner that no longer resolves; return 401 invalid_token at userinfo for the same cases. Also dispatch claims whose response: option is configured with strings (e.g. response: ["id_token"]), which were previously dropped from every response
    • #350 Discovery / Dynamic Client Registration spec compliance:
      • Advertise the standard implicit grant type instead of the internal implicit_oidc name (RFC 7591 ?2)
      • Breaking: omitted response_types / grant_types in a registration request now default to ["code"] / ["authorization_code"] per RFC 7591 ?2
      • Use RFC 7591 ?3.2.2 error codes (invalid_redirect_uri / invalid_client_metadata) instead of the invented invalid_client_params
      • Serve WebFinger as application/jrd+json with Access-Control-Allow-Origin: * (RFC 7033)
      • Create dynamically registered clients through application_model so custom models work with DCR
    • #351 Align OpenID Connect token/authorization responses with Doorkeeper's response contract: return the plaintext access token from the id_token token implicit response (fixes hash_token_secrets), define #issued_token on OIDC responses, and attach the ID token before after_successful_strategy_response fires
    • #353 Enrich Doorkeeper 6.0's RFC 8414 metadata document (/.well-known/oauth-authorization-server) with the OpenID Connect fields (jwks_uri, userinfo_endpoint, signing algs, claims) via the custom_metadata seam; app-configured custom_metadata keeps precedence. No behavior change on Doorkeeper < 6.0
    • #355 Compute at_hash from the plaintext access token instead of the stored value, fixing ID Token validation when hash_token_secrets is enabled
    • #360 Load the OpenID Connect constants with autoload instead of require, including the requests and responses this gem contributes to Doorkeeper's own namespace. No public constant changes name or moves (#362)
    • #363 Extend #349's id_token guard to the password grant with skip_client_authentication_for_password_grant ? previously returned an unhandled 500
    • #370 Correct the stale rake db:migrate command to rails db:migrate in the README, the #243 migration note, and the post_logout_redirect_uris missing-column error message
    • #372 Fix duplicate entries in the discovery document's claims_supported when a custom claim shadows a base claim (iss/sub/aud/exp/iat)
    • #373 Fix prompt=consent under Doorkeeper's api_only mode ? the consent step now returns the pre-authorization as JSON instead of attempting to render a template that ActionController::API cannot serve
    • #381 Echo the registered client_name in the Dynamic Client Registration response, as RFC 7591 ?3.2.1 requires the response to include all registered client metadata
    Changelog

    Sourced from doorkeeper-openid_connect's changelog.

    v2.0.0 (2026-09-22)

    [!IMPORTANT]

    • Breaking (class overrides): a configured id_token_class / user_info_class must now inherit from Doorkeeper::OpenidConnect::IdToken / UserInfo (#364)
    • Breaking (settings removed): the deprecated jws_private_key / jws_public_key initializer settings are gone (#387)
    • Breaking (constant renamed): Doorkeeper::OpenidConnect::HybridIdTokenConcern is now AtHashConcern, with no alias for the old name (#399)

    Coming from 1.10.x? Every breaking change listed under 2.0.0.beta1 below applies as well ? the post_logout_redirect_uris migration (#243), the id_token token response type change (#337), the removal of IdTokenToken (#338) and the Dynamic Client Registration defaults (#350). Those notes name HybridIdTokenConcern; read them as AtHashConcern, which is what 2.0.0 ships.

    Migration from Old Versions walks through each one.

    • Security: Register a dynamically registered client with the server's default_scopes when the registration request omits scope, instead of persisting an empty scope set. Only deployments that enable dynamic_client_registration are affected.
    • #364 Breaking: Require id_token_class / user_info_class overrides to inherit from Doorkeeper::OpenidConnect::IdToken / UserInfo (#344). Adds an IdToken#select_key hook returning the signing key and its algorithm together (IdToken::SigningKey) for per-client, rotating or multi-tenant keys, and binds the at_hash digest to that algorithm (OIDC Core ?3.2.2.10) rather than the global signing_algorithm
    • #387 Breaking: Remove the deprecated jws_private_key and jws_public_key initializer settings
    • #399 Breaking: Rename Doorkeeper::OpenidConnect::HybridIdTokenConcern to AtHashConcern. The old name described the id_token token response type as a hybrid flow, but OpenID Connect Core defines that response type under the Implicit Flow (?3.2) ? the Hybrid Flow response types of ?3.3 are not implemented by this gem. Removed without an alias: the constant only ever shipped in 2.0.0.beta1

    v2.0.0.beta1 (2026-08-20)

    [!IMPORTANT]

    • This is a prerelease. RubyGems does not resolve prereleases from an unqualified requirement, so it must be requested explicitly: gem "doorkeeper-openid_connect", "2.0.0.beta1"
    • Migration required: existing installations must add the post_logout_redirect_uris column ? rails generate doorkeeper:openid_connect:add_post_logout_redirect_uris followed by rails db:migrate (#243)
    • Breaking (hybrid response type): the id_token token response object is now the configured id_token_class extended with HybridIdTokenConcern, and a custom id_token_class must expose an #access_token reader (#337)
    • Breaking (constant removed): Doorkeeper::OpenidConnect::IdTokenToken is gone ? custom subclasses must subclass IdToken and include HybridIdTokenConcern (#338)
    • Breaking (Dynamic Client Registration): a registration request that omits response_types / grant_types now defaults to ["code"] / ["authorization_code"] per RFC 7591 ?2, instead of inheriting the server's global configuration (#350)

    Migration from Old Versions walks through each one.

    • #243 Add per-client post_logout_redirect_uris for RP-Initiated Logout, exposed via Doorkeeper::Application#post_logout_redirect_uris and #valid_post_logout_redirect_uri?(uri). URIs are validated with the same rules as redirect_uri; Dynamic Client Registration accepts and echoes them back
    • #320 Support mounting the engine under multiple named scopes ? use_doorkeeper_openid_connect as: :users makes each mount's discovery document advertise its own endpoints (#192)
    • #322 Fall back to Doorkeeper's issuer configuration when the OpenID Connect issuer is not set. The OpenID Connect value still takes precedence (#321)
    • #323 Resolve token_endpoint_auth_methods_supported from Doorkeeper's client authentication methods registry when available, falling back to legacy client_credentials_methods on older versions
    • #332 Fix grant_types_supported listing refresh_token twice when enabled via both grant_flows and use_refresh_token
    • #333 Emit the RFC 9207 iss parameter on id_token / id_token token authorization responses and on OIDC error redirects, and advertise authorization_response_iss_parameter_supported in the discovery document. No behavior change until Doorkeeper is configured with an issuer
    • #334 Allow Doorkeeper 6.0 (>= 5.5, < 7.0). Note: Doorkeeper 6.0's force_pkce applies to confidential clients too ? id_token / id_token token authorization requests are rejected unless they carry a code_challenge
    • #335 Add id_token_class and user_info_class config options for custom ID Token / UserInfo response objects
    • #337 Rework id_token_class / user_info_class internals ? lazy-resolve and validate configured classes at first use (fixes zeitwerk on Rails 7+) ? and deprecate Doorkeeper::OpenidConnect::IdTokenToken. A custom id_token_class must now expose an #access_token reader. Breaking (type change): the hybrid response token is now the configured id_token_class extended with HybridIdTokenConcern ? see the migration guide
    • #338 Breaking: Remove the deprecated IdTokenToken class. Custom subclasses must subclass IdToken and include HybridIdTokenConcern instead
    • #341 Fix dynamic client registration to respect the application_class configuration
    • #347 Omit symmetric (oct) keys from the JWKS endpoint when signing with an HMAC algorithm (RFC 7517)
    • #348 Authorization endpoint hardening:
      • Treat a malformed max_age parameter (e.g. max_age[]=1) as absent instead of a 500
      • Build prompt=login / prompt=select_account return URLs without mutating the shared request.query_parameters hash
      • Route internal errors (e.g. InvalidConfiguration) to a 500 instead of leaking them as authorization error redirects
    • #349 Fix several 500 errors in the claims pipeline: gracefully omit id_token when the access token has no resource owner, no application, or an owner that no longer resolves; return 401 invalid_token at userinfo for the same cases. Also dispatch claims whose response: option is configured with strings (e.g. response: ["id_token"]), which were previously dropped from every response
    • #350 Discovery / Dynamic Client Registration spec compliance:
      • Advertise the standard implicit grant type instead of the internal implicit_oidc name (RFC 7591 ?2)
      • Breaking: omitted response_types / grant_types in a registration request now default to ["code"] / ["authorization_code"] per RFC 7591 ?2
      • Use RFC 7591 ?3.2.2 error codes (invalid_redirect_uri / invalid_client_metadata) instead of the invented invalid_client_params

    ... (truncated)

    Commits
    • bd1d3e9 [ci skip] Fix CHANGELOG
    • 31213cc Merge pull request #400 from doorkeeper-gem/release/2.0.0
    • 7e1e2cd Merge pull request #403 from doorkeeper-gem/chore/pin-json-below-3
    • ad6ac58 Pin the development dependency on json below 3.0
    • 4e514f0 Merge pull request #397 from doorkeeper-gem/chore/rubocop-todo-delete
    • 04dcdd5 Merge pull request #399 from 55728/chore/rename-at-hash-concern
    • ab9f75e Merge pull request #396 from doorkeeper-gem/chore/rubocop-todo-drop-metrics
    • 341f862 Merge pull request #395 from doorkeeper-gem/chore/rubocop-metrics-refactors
    • 21395bc Release 2.0.0 :tada:
    • 4c55b37 Rename HybridIdTokenConcern to AtHashConcern
    • Additional commits viewable in compare view

    Updates `dalli` from 5.1.0 to 5.1.1
    Release notes

    Sourced from dalli's releases.

    v5.1.1

    Security release. Fixes GHSA-6wmv-xq9m-fmp7, a memcached command injection through numeric arguments. Upgrading is recommended.

    Security:

    • Fix memcached command injection through numeric arguments (GHSA-6wmv-xq9m-fmp7)
      • The default argument of incr/decr, and fetch_with_lock's lock_ttl and recache_threshold, were written into the meta protocol command without conversion, so a String containing CRLF injected additional memcached commands (e.g. set, flush_all) on the connection
      • These arguments must now be Integers, or Strings of decimal digits; anything else raises ArgumentError before a request is sent
      • As defense in depth, RequestFormatter now converts every numeric flag it writes (D, J, N, R, T) to an Integer
      • Affects 3.2.0 and later (3.2.x only with protocol: :meta); fixed in 5.1.1 and 4.3.4
      • Thanks to oss-security-shop for the report

    Performance:

    • Reduce Ruby overhead on the single-key get path by about 28% (#1160)
      • A plain get builds its mg request with one string interpolation instead of going through meta_get's keyword arguments, and skips option handling when called without options
      • A VA <size> f<flags> hit line is parsed in place instead of being split into tokens
      • The key check for control characters and whitespace uses a byte class that matches the same ASCII bytes as [\p{Cntrl}\s], about 5x faster; this applies to every operation that sends a key
      • Allocations per get hit drop from 23 to 16
      • Thanks to Julian Richard Contreras for this contribution
    • Speed up multi-server get_multi by about 30% (4 servers, 100 keys), and bring small batches in line with 2.7.11 (#1161)
      • Each server's queries and terminating noop are sent before the next server's are built, so memcached answers earlier servers while later ones are prepared
      • A server's queries are built in one pass with RequestFormatter.multi_meta_get, and plain get_multi no longer requests the CAS value it discards (get_multi_cas still does)
      • Pipelined replies are parsed in one pass over the returned flags
      • Routing many keys checks each server's alive? once per call instead of twice per key, and the ring's binary search runs over plain integers
      • Thanks to Julian Richard Contreras for this contribution

    Development:

    • Fix offenses reported by RuboCop 1.91 and require rubocop >= 1.91 (#1162)
      • RuboCop 1.91 adds Style/DirectiveScope; single-statement disable/enable pairs become disable-next directives, which older RuboCop versions do not recognize
      • Removes a misplaced # encoding: ascii comment in client.rb that Ruby had always ignored
    Changelog

    Sourced from dalli's changelog.

    5.1.1

    Security:

    • Fix memcached command injection through numeric arguments (GHSA-6wmv-xq9m-fmp7)
      • The default argument of incr/decr, and fetch_with_lock's lock_ttl and recache_threshold, were written into the meta protocol command without conversion, so a String containing CRLF injected additional memcached commands (e.g. set, flush_all) on the connection
      • These arguments must now be Integers, or Strings of decimal digits; anything else raises ArgumentError before a request is sent
      • As defense in depth, RequestFormatter now converts every numeric flag it writes (D, J, N, R, T) to an Integer
      • Affects 3.2.0 and later (3.2.x only with protocol: :meta); fixed in 5.1.1 and 4.3.4
      • Thanks to oss-security-shop for the report

    Performance:

    • Reduce Ruby overhead on the single-key get path by about 28% (#1160)
      • A plain get builds its mg request with one string interpolation instead of going through meta_get's keyword arguments, and skips option handling when called without options
      • A VA <size> f<flags> hit line is parsed in place instead of being split into tokens
      • The key check for control characters and whitespace uses a byte class that matches the same ASCII bytes as [\p{Cntrl}\s], about 5x faster; this applies to every operation that sends a key
      • Allocations per get hit drop from 23 to 16
      • Thanks to Julian Richard Contreras for this contribution
    • Speed up multi-server get_multi by about 30% (4 servers, 100 keys), and bring small batches in line with 2.7.11 (#1161)
      • Each server's queries and terminating noop are sent before the next server's are built, so memcached answers earlier servers while later ones are prepared
      • A server's queries are built in one pass with RequestFormatter.multi_meta_get, and plain get_multi no longer requests the CAS value it discards (get_multi_cas still does)
      • Pipelined replies are parsed in one pass over the returned flags
      • Routing many keys checks each server's alive? once per call instead of twice per key, and the ring's binary search runs over plain integers
      • Thanks to Julian Richard Contreras for this contribution

    Development:

    • Fix offenses reported by RuboCop 1.91 and require rubocop >= 1.91 (#1162)
      • RuboCop 1.91 adds Style/DirectiveScope; single-statement disable/enable pairs become disable-next directives, which older RuboCop versions do not recognize
      • Removes a misplaced # encoding: ascii comment in client.rb that Ruby had always ignored
    Commits
    • 7bd7daf Merge commit from fork
    • e3b73f6 Prepare 5.1.1 release
    • 5d6b470 Reject non-integer numeric flags in meta protocol commands
    • 473932d Merge pull request #1163 from petergoldstein/docs/changelog-1160-1161-1162
    • 4c20d0c Update CHANGELOG for #1160, #1161 and #1162
    • a2dac30 Merge pull request #1161 from radixdev/perf/faster-multi-server-get-multi
    • dd81192 Add PR number to changelog entry
    • 7b974e5 Speed up multi-server get_multi
    • 3c6e9c6 Merge pull request #1160 from radixdev/perf/faster-single-get
    • 758d1b9 Treat false options like nil on the get fast path
    • Additional commits viewable in compare view

    Updates `aws-sdk-s3` from 1.232.1 to 1.232.2
    Changelog

    Sourced from aws-sdk-s3's changelog.

    1.232.2 (2026-09-25)

    • Issue - Ensure the internally-created executor is shutdown on error in TransferManager and Aws::S3::Object resource methods, preventing leaked worker threads on multipart transfer failures (#3419).
    Commits

    Updates `herb` from 0.10.4 to 0.11.0
    Release notes

    Sourced from herb's releases.

    v0.11.0

    Herb v0.11

    Herb v0.11 ships alongside ReActionView v0.6. Check out the "What's new in Herb v0.11" post on the Herb Blog.

    Parser

    • Introduce ERBIterationBlockNode and iteration_nodes option by @?marcoroth in marcoroth/herb#1912
    • Introduce HerbDirectiveNode and HerbStateDirectiveNode by @?marcoroth in marcoroth/herb#2435
    • Introduce ERBCommentNode by @?marcoroth in marcoroth/herb#2605
    • Introduce XMLProcessingInstructionNode by @?marcoroth in marcoroth/herb#2266
    • Add an erb_openers option for custom ERB tag openers by @?marcoroth in #2487, #2491 and #2645
    • Follow HTML5 tokenizer for attribute names/values and comments by @?marcoroth in marcoroth/herb#2593
    • Treat every raw text element, including <textarea>, as raw text by @?marcoroth in #2596 and #2601
    • Treat <title> content as text by @?marcoroth in marcoroth/herb#2597
    • Key foreign content on a kind and the element name by @?marcoroth in marcoroth/herb#2598
    • Count characters, not bytes, when computing columns by @?marcoroth in marcoroth/herb#2442
    • Convert dynamic boolean attributes to conditional attributes by @?marcoroth in marcoroth/herb#2112
    • Convert literals to static text in transform_conditionals by @?marcoroth in marcoroth/herb#2302
    • Don't transform locals that shadow Action View helpers by @?marcoroth in #1900 and #2076
    • Only analyze receiver-less render calls as Action View renders by @?marcoroth in marcoroth/herb#2071
    • Don't flag render layout: with a blo... _Description has been truncated_ You can view, comment on, or merge this pull request online at: https://github.com/openstreetmap/openstreetmap-website/pull/7452 -- Commit Summary -- * Bump the dependencies group across 1 directory with 11 updates -- File Changes -- M Gemfile.lock (24) -- Patch Links -- https://github.com/openstreetmap/openstreetmap-website/pull/7452.patch https://github.com/openstreetmap/openstreetmap-website/pull/7452.diff -- Reply to this email directly or view it on GitHub: https://github.com/openstreetmap/openstreetmap-website/pull/7452 You are receiving this because you are subscribed to this thread. Message ID: -------------- next part -------------- An HTML attachment was scrubbed... URL: From notifications at github.com Thu Oct 1 11:02:43 2026 From: notifications at github.com (Tom Hughes) Date: Thu, 01 Oct 2026 04:02:43 -0700 Subject: [openstreetmap/openstreetmap-website] Bump rails from 8.1.3.1 to 8.1.4 in the rails group across 1 directory (PR #7444) In-Reply-To: References: Message-ID: Merged #7444 into master. -- Reply to this email directly or view it on GitHub: https://github.com/openstreetmap/openstreetmap-website/pull/7444#event-32244764050 You are receiving this because you are subscribed to this thread. Message ID: -------------- next part -------------- An HTML attachment was scrubbed... URL: From notifications at github.com Thu Oct 1 11:11:22 2026 From: notifications at github.com (dependabot[bot]) Date: Thu, 01 Oct 2026 04:11:22 -0700 Subject: [openstreetmap/openstreetmap-website] Bump the dependencies group across 1 directory with 11 updates (PR #7452) In-Reply-To: References: Message-ID: Closed #7452. -- Reply to this email directly or view it on GitHub: https://github.com/openstreetmap/openstreetmap-website/pull/7452#event-32245314732 You are receiving this because you are subscribed to this thread. Message ID: -------------- next part -------------- An HTML attachment was scrubbed... URL: From notifications at github.com Thu Oct 1 11:11:21 2026 From: notifications at github.com (dependabot[bot]) Date: Thu, 01 Oct 2026 04:11:21 -0700 Subject: [openstreetmap/openstreetmap-website] Bump the dependencies group across 1 directory with 11 updates (PR #7452) In-Reply-To: References: Message-ID: dependabot[bot] left a comment (openstreetmap/openstreetmap-website#7452) Looks like these dependencies are updatable in another way, so this is no longer needed. -- Reply to this email directly or view it on GitHub: https://github.com/openstreetmap/openstreetmap-website/pull/7452#issuecomment-5930128385 You are receiving this because you are subscribed to this thread. Message ID: -------------- next part -------------- An HTML attachment was scrubbed... URL: From notifications at github.com Thu Oct 1 11:11:43 2026 From: notifications at github.com (dependabot[bot]) Date: Thu, 01 Oct 2026 04:11:43 -0700 Subject: [openstreetmap/openstreetmap-website] Bump the dependencies group across 1 directory with 10 updates (PR #7453) Message-ID: Bumps the dependencies group with 10 updates in the / directory: | Package | From | To | | --- | --- | --- | | [activerecord-postgis](https://github.com/seuros/activerecord-postgis) | `0.6.0` | `0.6.1` | | [actionpack-page_caching](https://github.com/rails/actionpack-page_caching) | `1.2.4` | `1.2.5` | | [doorkeeper](https://github.com/doorkeeper-gem/doorkeeper) | `5.9.7` | `5.9.9` | | [doorkeeper-openid_connect](https://github.com/doorkeeper-gem/doorkeeper-openid_connect) | `1.10.5` | `2.0.0` | | [dalli](https://github.com/petergoldstein/dalli) | `5.1.0` | `5.1.1` | | [aws-sdk-s3](https://github.com/aws/aws-sdk-ruby) | `1.232.1` | `1.232.2` | | [herb](https://github.com/marcoroth/herb) | `0.10.4` | `0.11.0` | | [database_consistency](https://github.com/djezzzl/database_consistency) | `3.0.12` | `3.0.13` | | [aws-partitions](https://github.com/aws/aws-sdk-ruby) | `1.1289.0` | `1.1291.0` | | [bindata](https://github.com/dmendel/bindata) | `3.0.0` | `3.0.1` | Updates `activerecord-postgis` from 0.6.0 to 0.6.1
      Release notes

      Sourced from activerecord-postgis's releases.

      activerecord-postgis: v0.6.1

      0.6.1 (2026-09-22)

      Bug Fixes

      • don't memoize RGeo factory in spatial types (#20) (d9e9f08)
      Changelog

      Sourced from activerecord-postgis's changelog.

      0.6.1 (2026-09-22)

      Bug Fixes

      • don't memoize RGeo factory in spatial types (#20) (d9e9f08)
      Commits

      Updates `actionpack-page_caching` from 1.2.4 to 1.2.5
      Changelog

      Sourced from actionpack-page_caching's changelog.

      1.2.5 (September 21, 2026)

      • Fix directory check for directory with shared prefix

      John Hawthorn

      Commits

      Updates `doorkeeper` from 5.9.7 to 5.9.9
      Release notes

      Sourced from doorkeeper's releases.

      v5.9.9

      • Fix: AuthorizedApplicationsController now answers 401 Unauthorized instead of running with a nil resource owner, which listed and revoked every token that has no resource owner ? the ones the client credentials flow issues. Affected host applications are those whose resource_owner_authenticator answers nil without halting the request itself; the generated initializer's example redirects and is not affected.
      • Fix: AuthorizationsController#destroy now validates the client and redirect URI before producing the deny response, and renders ? never redirects ? when validation fails. Previously the deny path performed no OAuth-layer validation at all, allowing an open redirect to an attacker-controlled origin with the OAuth state attached. Also reject unregistered response_type values on the authorization endpoint rather than resolving them through the constantize fallback.
      • Fix: refuse redirect URIs with a script scheme (javascript, vbscript, data) both when an application is registered and at authorization time, regardless of forbid_redirect_uri. Such a URI is never a legitimate redirection endpoint, and with response_mode=form_post it became the action of the auto-submitting form the authorization server renders on its own origin. Already stored records with such a URI are now refused with invalid_redirect_uri before the consent screen is shown.
      • #1938 Fix: a request body ActionDispatch cannot parse (malformed JSON under a JSON content type, say) no longer raises ActionDispatch::Http::Parameters::ParseError out of Doorkeeper::OAuth::Token.from_request and doorkeeper_token. Since 5.9.7 the RFC 6750 ?2 multi-method check read the body on every request, so such a request raised even when it carried a valid Bearer header. The body is now treated as carrying no token, the same way ActionDispatch's own #filtered_parameters treats that error.
      Changelog

      Sourced from doorkeeper's changelog.

      Changelog

      See https://github.com/doorkeeper-gem/doorkeeper/wiki/Migration-from-old-versions for upgrade guides.

      User-visible changes worth mentioning.

      main

      • [#PR ID] Description of the change.
      • #1960 Ignore the port of http://localhost redirect URIs like that of loopback IP literals (RFC 8252 ?7.3 / ?8.3).
      • #1959 A custom access_token_generator now receives the token's resource (RFC 8707), so a JWT generator can set aud.

      6.0.0.rc2

      Please make sure you read the Upgrade guides and changelog below before the update since this version includes breaking changes.

      • #1951 Fix: the built gem no longer contains vendor/bundle. The gemspec globed all of vendor/, which swept in the bundle installed by the release workflow; 6.0.0.rc1 is a 44.4 MB download against 154 KB for 6.0.0.beta2.
      • Fix: AuthorizedApplicationsController now answers 401 Unauthorized instead of running with a nil resource owner, which listed and revoked every token that has no resource owner ? the ones the client credentials flow issues. Affected host applications are those whose resource_owner_authenticator answers nil without halting the request itself; the generated initializer's example redirects and is not affected.
      • Fix: AuthorizationsController#destroy now validates the client and redirect URI before producing the deny response, and renders ? never redirects ? when validation fails. Previously the deny path performed no OAuth-layer validation at all, allowing an open redirect to an attacker-controlled origin with the OAuth state attached. Also reject unregistered response_type values on the authorization endpoint rather than resolving them through the constantize fallback.
      • Fix: refuse redirect URIs with a script scheme (javascript, vbscript, data) both when an application is registered and at authorization time, regardless of forbid_redirect_uri. Such a URI is never a legitimate redirection endpoint, and with response_mode=form_post it became the action of the auto-submitting form the authorization server renders on its own origin. Already stored records with such a URI are now refused with invalid_redirect_uri before the consent screen is shown.
      • #1932 Fix: keep the scope originally granted by the resource owner on refresh tokens (RFC 6749 ?6), so a chain narrowed on one refresh can return to its granted scope. Tracked in a new refresh_token_scopes column; existing installations opt in with rails generate doorkeeper:refresh_token_scopes.
      • #1933 Warn at boot when the implicit or password grant flow is enabled: both are deprecated by RFC 9700 (OAuth 2.0 Security BCP) and removed from OAuth 2.1, and may be removed in a future Doorkeeper release.
      • #1915 Fix: fetching a client's jwks_uri now falls back to the other addresses returned by DNS when the first one cannot be connected to.
      • #1934 The refresh_token grant now consults custom_access_token_expires_in (with Doorkeeper::OAuth::REFRESH_TOKEN as the context grant type) for the TTL of the refreshed access token. A callable that returns nil for this grant, or no callable at all, keeps inheriting the TTL of the token being refreshed as before. A callable that returns a value unconditionally now applies to refreshes as well.
      • #1935 Add opt-in public_client_access_token_expires_in configuration option: a ceiling for the lifetime of access tokens issued to public (non-confidential) clients by any grant, refresh_token included, as OAuth 2.1 Section 2.4 requires the exposure of tokens issued to unauthenticated clients to be limited. Confidential clients are not affected.
      • #1938 Fix: a request body ActionDispatch cannot parse (malformed JSON under a JSON content type, say) no longer raises ActionDispatch::Http::Parameters::ParseError out of Doorkeeper::OAuth::Token.from_request and doorkeeper_token. Since 5.9.7 the RFC 6750 ?2 multi-method check read the body on every request, so such a request raised even when it carried a valid Bearer header. The body is now treated as carrying no token, the same way ActionDispatch's own #filtered_parameters treats that error.
      • #1950 Document hash_token_secrets / hash_application_secrets fallback: as a migration-period setting that should be removed once every row is hashed, and warn at boot for as long as one is configured. While a :plain fallback is active the stored value is itself a valid credential, so those columns need protecting as carefully as plaintext ones.
      • #1953 Fix: public_client_access_token_expires_in now also holds under reuse_access_token and with String TTLs, and the refresh_token grant hands custom_access_token_expires_in and resource_indicator_validator what every other grant does.

      6.0.0.rc1

      Please make sure you read the Upgrade guides and changelog below before the update since this version includes breaking changes.

      • Require Ruby >= 3.2 in the gemspec, matching the CI matrix (3.2 / 3.3 / 3.4 / 4.0). Ruby 2.7, 3.0 and 3.1 have reached end-of-life.
      • Fix: the client_secret_basic strategy now requires a client_id sent in the request body to name the same client as the Authorization: Basic header ? the RFC 7521 ?4.2 agreement check private_key_jwt already applies to an assertion's issuer. A request presenting Basic credentials for one client and a client_id for another was authenticated as the Basic client, silently discarding the other identity. A bare client_id is not a client authentication method of its own, so the RFC 6749 ?2.3 multiple-methods check does not (and should not) count it.
      • #1906 Internal: exempt Doorkeeper::Config from Metrics/ClassLength with a directive on the class itself instead of raising the cop's global ceiling, so adding a configuration option no longer trips the limit.
      • #1907 Fix: a resource parameter no longer produces a 500 at the authorization endpoint when resource_indicator_validator is configured without the doorkeeper:resource_indicators migration. Such a request is now answered with server_error, as the token endpoint already did, and the missing migration is warned about at boot.
      • #1909 Add Rails 8.1 to CI test matrix.
      • #1910 Add opt-in validate_client_before_resource_owner_authentication configuration option: the authorization endpoint validates client_id and redirect_uri before authenticating the resource owner, so users are not sent through login for a request that can only fail.
      • #1916 Fix broken Coveralls coverage reporting.
      • #1918 The api_only controller specs no longer load the real controller sources, which detached the coverage of every other example that ran them and made the reported coverage depend on the random example order.
      • #1923 Fix: the fallback secret upgrade no longer writes the matched secret back over a value stored in the meantime, which could undo a concurrent #renew_secret and leave the superseded secret valid. Active Record writes the upgrade conditionally on the column still holding the value that matched; other ORMs can implement the new write_upgraded_secret hook. The Active Record write is a single update_all statement, so model callbacks and validations no longer run on this upgrade (timestamps and optimistic locking are still maintained).
      • #1925 Internal: pin the development dependency on json below 3.0. json 3 removed the positional options Hash from JSON.parse and the quirks_mode option from JSON.generate, both of which Active Support still uses, so the suite could not run on any released Rails version.
      • #1926 [BREAKING] Fix: private_key_jwt client authentication no longer accepts an audience derived from the request's Host header, which let a client assertion minted for another authorization server be replayed here. A server that configures neither issuer nor Rails' default_url_options[:host] now has no acceptable audience and refuses every assertion, and is warned about it at boot.
      • [BREAKING] Refuse requests that transmit the access token by more than one method (RFC 6750 ?2) with an invalid_request error, instead of silently authorizing with the first method that yielded a token and discarding the rest. The form-encoded body (?2.2) and the URI query (?2.3) count as two methods even though Rails and Rack merge them into a single params hash, and the same token repeated across two methods is refused too ? ?2 forbids the second method, not a disagreement between the two.
        • Only the built-in extraction methods take part in the check; a custom callable in access_token_methods keeps the historical first-wins behavior and is never invoked more than once.
        • Doorkeeper::OAuth::Token.from_request / .authenticate raise Doorkeeper::Errors::MultipleAccessTokenMethods. Doorkeeper.authenticate and every doorkeeper_token helper (Rails, Grape, and Doorkeeper's own controllers) keep their token-or-nil contract, so doorkeeper_authorize! renders the refusal through a new doorkeeper_bad_request_render_options(error:) hook (head 400 unless you override it).

      ... (truncated)

      Commits
      • 6f65d41 Backport gemspec to avoid vendor/bundle
      • 1879ce4 Release 5.9.9 :tada:
      • 9403233 Merge commit from fork
      • 6d711eb Merge commit from fork
      • 7504992 Refuse redirect URIs with a script scheme
      • de57e75 Merge commit from fork
      • 0960bd7 Merge back release workflow for 5.9 branch
      • 9cafb36 Validate the client and redirect URI on the authorization deny path
      • f6ec046 Refuse authorized applications requests with no resource owner
      • e72e53f Merge pull request #1939 from doorkeeper-gem/chore/bump-5.9.8
      • Additional commits viewable in compare view

      Updates `doorkeeper-openid_connect` from 1.10.5 to 2.0.0
      Release notes

      Sourced from doorkeeper-openid_connect's releases.

      v2.0.0

      • Security: Register a dynamically registered client with the server's default_scopes when the registration request omits scope, instead of persisting an empty scope set. Only deployments that enable dynamic_client_registration are affected.
      • #364 Breaking: Require id_token_class / user_info_class overrides to inherit from Doorkeeper::OpenidConnect::IdToken / UserInfo (#344). Adds an IdToken#select_key hook returning the signing key and its algorithm together (IdToken::SigningKey) for per-client, rotating or multi-tenant keys, and binds the at_hash digest to that algorithm (OIDC Core ?3.2.2.10) rather than the global signing_algorithm
      • #387 Breaking: Remove the deprecated jws_private_key and jws_public_key initializer settings
      • #399 Breaking: Rename Doorkeeper::OpenidConnect::HybridIdTokenConcern to AtHashConcern. The old name described the id_token token response type as a hybrid flow, but OpenID Connect Core defines that response type under the Implicit Flow (?3.2) ? the Hybrid Flow response types of ?3.3 are not implemented by this gem. Removed without an alias: the constant only ever shipped in 2.0.0.beta1

      v2.0.0.beta1

      [!IMPORTANT]

      • This is a prerelease. RubyGems does not resolve prereleases from an unqualified requirement, so it must be requested explicitly: gem "doorkeeper-openid_connect", "2.0.0.beta1"
      • Migration required: existing installations must add the post_logout_redirect_uris column ? rails generate doorkeeper:openid_connect:add_post_logout_redirect_uris followed by rails db:migrate (#243)
      • Breaking (hybrid response type): the id_token token response object is now the configured id_token_class extended with HybridIdTokenConcern, and a custom id_token_class must expose an #access_token reader (#337)
      • Breaking (constant removed): Doorkeeper::OpenidConnect::IdTokenToken is gone ? custom subclasses must subclass IdToken and include HybridIdTokenConcern (#338)
      • Breaking (Dynamic Client Registration): a registration request that omits response_types / grant_types now defaults to ["code"] / ["authorization_code"] per RFC 7591 ?2, instead of inheriting the server's global configuration (#350)

      Migration from Old Versions walks through each one.

      • #243 Add per-client post_logout_redirect_uris for RP-Initiated Logout, exposed via Doorkeeper::Application#post_logout_redirect_uris and #valid_post_logout_redirect_uri?(uri). URIs are validated with the same rules as redirect_uri; Dynamic Client Registration accepts and echoes them back
      • #320 Support mounting the engine under multiple named scopes ? use_doorkeeper_openid_connect as: :users makes each mount's discovery document advertise its own endpoints (#192)
      • #322 Fall back to Doorkeeper's issuer configuration when the OpenID Connect issuer is not set. The OpenID Connect value still takes precedence (#321)
      • #323 Resolve token_endpoint_auth_methods_supported from Doorkeeper's client authentication methods registry when available, falling back to legacy client_credentials_methods on older versions
      • #332 Fix grant_types_supported listing refresh_token twice when enabled via both grant_flows and use_refresh_token
      • #333 Emit the RFC 9207 iss parameter on id_token / id_token token authorization responses and on OIDC error redirects, and advertise authorization_response_iss_parameter_supported in the discovery document. No behavior change until Doorkeeper is configured with an issuer
      • #334 Allow Doorkeeper 6.0 (>= 5.5, < 7.0). Note: Doorkeeper 6.0's force_pkce applies to confidential clients too ? id_token / id_token token authorization requests are rejected unless they carry a code_challenge
      • #335 Add id_token_class and user_info_class config options for custom ID Token / UserInfo response objects
      • #337 Rework id_token_class / user_info_class internals ? lazy-resolve and validate configured classes at first use (fixes zeitwerk on Rails 7+) ? and deprecate Doorkeeper::OpenidConnect::IdTokenToken. A custom id_token_class must now expose an #access_token reader. Breaking (type change): the hybrid response token is now the configured id_token_class extended with HybridIdTokenConcern ? see the migration guide
      • #338 Breaking: Remove the deprecated IdTokenToken class. Custom subclasses must subclass IdToken and include HybridIdTokenConcern instead
      • #341 Fix dynamic client registration to respect the application_class configuration
      • #347 Omit symmetric (oct) keys from the JWKS endpoint when signing with an HMAC algorithm (RFC 7517)
      • #348 Authorization endpoint hardening:
        • Treat a malformed max_age parameter (e.g. max_age[]=1) as absent instead of a 500
        • Build prompt=login / prompt=select_account return URLs without mutating the shared request.query_parameters hash
        • Route internal errors (e.g. InvalidConfiguration) to a 500 instead of leaking them as authorization error redirects
      • #349 Fix several 500 errors in the claims pipeline: gracefully omit id_token when the access token has no resource owner, no application, or an owner that no longer resolves; return 401 invalid_token at userinfo for the same cases. Also dispatch claims whose response: option is configured with strings (e.g. response: ["id_token"]), which were previously dropped from every response
      • #350 Discovery / Dynamic Client Registration spec compliance:
        • Advertise the standard implicit grant type instead of the internal implicit_oidc name (RFC 7591 ?2)
        • Breaking: omitted response_types / grant_types in a registration request now default to ["code"] / ["authorization_code"] per RFC 7591 ?2
        • Use RFC 7591 ?3.2.2 error codes (invalid_redirect_uri / invalid_client_metadata) instead of the invented invalid_client_params
        • Serve WebFinger as application/jrd+json with Access-Control-Allow-Origin: * (RFC 7033)
        • Create dynamically registered clients through application_model so custom models work with DCR
      • #351 Align OpenID Connect token/authorization responses with Doorkeeper's response contract: return the plaintext access token from the id_token token implicit response (fixes hash_token_secrets), define #issued_token on OIDC responses, and attach the ID token before after_successful_strategy_response fires
      • #353 Enrich Doorkeeper 6.0's RFC 8414 metadata document (/.well-known/oauth-authorization-server) with the OpenID Connect fields (jwks_uri, userinfo_endpoint, signing algs, claims) via the custom_metadata seam; app-configured custom_metadata keeps precedence. No behavior change on Doorkeeper < 6.0
      • #355 Compute at_hash from the plaintext access token instead of the stored value, fixing ID Token validation when hash_token_secrets is enabled
      • #360 Load the OpenID Connect constants with autoload instead of require, including the requests and responses this gem contributes to Doorkeeper's own namespace. No public constant changes name or moves (#362)
      • #363 Extend #349's id_token guard to the password grant with skip_client_authentication_for_password_grant ? previously returned an unhandled 500
      • #370 Correct the stale rake db:migrate command to rails db:migrate in the README, the #243 migration note, and the post_logout_redirect_uris missing-column error message
      • #372 Fix duplicate entries in the discovery document's claims_supported when a custom claim shadows a base claim (iss/sub/aud/exp/iat)
      • #373 Fix prompt=consent under Doorkeeper's api_only mode ? the consent step now returns the pre-authorization as JSON instead of attempting to render a template that ActionController::API cannot serve
      • #381 Echo the registered client_name in the Dynamic Client Registration response, as RFC 7591 ?3.2.1 requires the response to include all registered client metadata
      Changelog

      Sourced from doorkeeper-openid_connect's changelog.

      v2.0.0 (2026-09-22)

      [!IMPORTANT]

      • Breaking (class overrides): a configured id_token_class / user_info_class must now inherit from Doorkeeper::OpenidConnect::IdToken / UserInfo (#364)
      • Breaking (settings removed): the deprecated jws_private_key / jws_public_key initializer settings are gone (#387)
      • Breaking (constant renamed): Doorkeeper::OpenidConnect::HybridIdTokenConcern is now AtHashConcern, with no alias for the old name (#399)

      Coming from 1.10.x? Every breaking change listed under 2.0.0.beta1 below applies as well ? the post_logout_redirect_uris migration (#243), the id_token token response type change (#337), the removal of IdTokenToken (#338) and the Dynamic Client Registration defaults (#350). Those notes name HybridIdTokenConcern; read them as AtHashConcern, which is what 2.0.0 ships.

      Migration from Old Versions walks through each one.

      • Security: Register a dynamically registered client with the server's default_scopes when the registration request omits scope, instead of persisting an empty scope set. Only deployments that enable dynamic_client_registration are affected.
      • #364 Breaking: Require id_token_class / user_info_class overrides to inherit from Doorkeeper::OpenidConnect::IdToken / UserInfo (#344). Adds an IdToken#select_key hook returning the signing key and its algorithm together (IdToken::SigningKey) for per-client, rotating or multi-tenant keys, and binds the at_hash digest to that algorithm (OIDC Core ?3.2.2.10) rather than the global signing_algorithm
      • #387 Breaking: Remove the deprecated jws_private_key and jws_public_key initializer settings
      • #399 Breaking: Rename Doorkeeper::OpenidConnect::HybridIdTokenConcern to AtHashConcern. The old name described the id_token token response type as a hybrid flow, but OpenID Connect Core defines that response type under the Implicit Flow (?3.2) ? the Hybrid Flow response types of ?3.3 are not implemented by this gem. Removed without an alias: the constant only ever shipped in 2.0.0.beta1

      v2.0.0.beta1 (2026-08-20)

      [!IMPORTANT]

      • This is a prerelease. RubyGems does not resolve prereleases from an unqualified requirement, so it must be requested explicitly: gem "doorkeeper-openid_connect", "2.0.0.beta1"
      • Migration required: existing installations must add the post_logout_redirect_uris column ? rails generate doorkeeper:openid_connect:add_post_logout_redirect_uris followed by rails db:migrate (#243)
      • Breaking (hybrid response type): the id_token token response object is now the configured id_token_class extended with HybridIdTokenConcern, and a custom id_token_class must expose an #access_token reader (#337)
      • Breaking (constant removed): Doorkeeper::OpenidConnect::IdTokenToken is gone ? custom subclasses must subclass IdToken and include HybridIdTokenConcern (#338)
      • Breaking (Dynamic Client Registration): a registration request that omits response_types / grant_types now defaults to ["code"] / ["authorization_code"] per RFC 7591 ?2, instead of inheriting the server's global configuration (#350)

      Migration from Old Versions walks through each one.

      • #243 Add per-client post_logout_redirect_uris for RP-Initiated Logout, exposed via Doorkeeper::Application#post_logout_redirect_uris and #valid_post_logout_redirect_uri?(uri). URIs are validated with the same rules as redirect_uri; Dynamic Client Registration accepts and echoes them back
      • #320 Support mounting the engine under multiple named scopes ? use_doorkeeper_openid_connect as: :users makes each mount's discovery document advertise its own endpoints (#192)
      • #322 Fall back to Doorkeeper's issuer configuration when the OpenID Connect issuer is not set. The OpenID Connect value still takes precedence (#321)
      • #323 Resolve token_endpoint_auth_methods_supported from Doorkeeper's client authentication methods registry when available, falling back to legacy client_credentials_methods on older versions
      • #332 Fix grant_types_supported listing refresh_token twice when enabled via both grant_flows and use_refresh_token
      • #333 Emit the RFC 9207 iss parameter on id_token / id_token token authorization responses and on OIDC error redirects, and advertise authorization_response_iss_parameter_supported in the discovery document. No behavior change until Doorkeeper is configured with an issuer
      • #334 Allow Doorkeeper 6.0 (>= 5.5, < 7.0). Note: Doorkeeper 6.0's force_pkce applies to confidential clients too ? id_token / id_token token authorization requests are rejected unless they carry a code_challenge
      • #335 Add id_token_class and user_info_class config options for custom ID Token / UserInfo response objects
      • #337 Rework id_token_class / user_info_class internals ? lazy-resolve and validate configured classes at first use (fixes zeitwerk on Rails 7+) ? and deprecate Doorkeeper::OpenidConnect::IdTokenToken. A custom id_token_class must now expose an #access_token reader. Breaking (type change): the hybrid response token is now the configured id_token_class extended with HybridIdTokenConcern ? see the migration guide
      • #338 Breaking: Remove the deprecated IdTokenToken class. Custom subclasses must subclass IdToken and include HybridIdTokenConcern instead
      • #341 Fix dynamic client registration to respect the application_class configuration
      • #347 Omit symmetric (oct) keys from the JWKS endpoint when signing with an HMAC algorithm (RFC 7517)
      • #348 Authorization endpoint hardening:
        • Treat a malformed max_age parameter (e.g. max_age[]=1) as absent instead of a 500
        • Build prompt=login / prompt=select_account return URLs without mutating the shared request.query_parameters hash
        • Route internal errors (e.g. InvalidConfiguration) to a 500 instead of leaking them as authorization error redirects
      • #349 Fix several 500 errors in the claims pipeline: gracefully omit id_token when the access token has no resource owner, no application, or an owner that no longer resolves; return 401 invalid_token at userinfo for the same cases. Also dispatch claims whose response: option is configured with strings (e.g. response: ["id_token"]), which were previously dropped from every response
      • #350 Discovery / Dynamic Client Registration spec compliance:
        • Advertise the standard implicit grant type instead of the internal implicit_oidc name (RFC 7591 ?2)
        • Breaking: omitted response_types / grant_types in a registration request now default to ["code"] / ["authorization_code"] per RFC 7591 ?2
        • Use RFC 7591 ?3.2.2 error codes (invalid_redirect_uri / invalid_client_metadata) instead of the invented invalid_client_params

      ... (truncated)

      Commits
      • bd1d3e9 [ci skip] Fix CHANGELOG
      • 31213cc Merge pull request #400 from doorkeeper-gem/release/2.0.0
      • 7e1e2cd Merge pull request #403 from doorkeeper-gem/chore/pin-json-below-3
      • ad6ac58 Pin the development dependency on json below 3.0
      • 4e514f0 Merge pull request #397 from doorkeeper-gem/chore/rubocop-todo-delete
      • 04dcdd5 Merge pull request #399 from 55728/chore/rename-at-hash-concern
      • ab9f75e Merge pull request #396 from doorkeeper-gem/chore/rubocop-todo-drop-metrics
      • 341f862 Merge pull request #395 from doorkeeper-gem/chore/rubocop-metrics-refactors
      • 21395bc Release 2.0.0 :tada:
      • 4c55b37 Rename HybridIdTokenConcern to AtHashConcern
      • Additional commits viewable in compare view

      Updates `dalli` from 5.1.0 to 5.1.1
      Release notes

      Sourced from dalli's releases.

      v5.1.1

      Security release. Fixes GHSA-6wmv-xq9m-fmp7, a memcached command injection through numeric arguments. Upgrading is recommended.

      Security:

      • Fix memcached command injection through numeric arguments (GHSA-6wmv-xq9m-fmp7)
        • The default argument of incr/decr, and fetch_with_lock's lock_ttl and recache_threshold, were written into the meta protocol command without conversion, so a String containing CRLF injected additional memcached commands (e.g. set, flush_all) on the connection
        • These arguments must now be Integers, or Strings of decimal digits; anything else raises ArgumentError before a request is sent
        • As defense in depth, RequestFormatter now converts every numeric flag it writes (D, J, N, R, T) to an Integer
        • Affects 3.2.0 and later (3.2.x only with protocol: :meta); fixed in 5.1.1 and 4.3.4
        • Thanks to oss-security-shop for the report

      Performance:

      • Reduce Ruby overhead on the single-key get path by about 28% (#1160)
        • A plain get builds its mg request with one string interpolation instead of going through meta_get's keyword arguments, and skips option handling when called without options
        • A VA <size> f<flags> hit line is parsed in place instead of being split into tokens
        • The key check for control characters and whitespace uses a byte class that matches the same ASCII bytes as [\p{Cntrl}\s], about 5x faster; this applies to every operation that sends a key
        • Allocations per get hit drop from 23 to 16
        • Thanks to Julian Richard Contreras for this contribution
      • Speed up multi-server get_multi by about 30% (4 servers, 100 keys), and bring small batches in line with 2.7.11 (#1161)
        • Each server's queries and terminating noop are sent before the next server's are built, so memcached answers earlier servers while later ones are prepared
        • A server's queries are built in one pass with RequestFormatter.multi_meta_get, and plain get_multi no longer requests the CAS value it discards (get_multi_cas still does)
        • Pipelined replies are parsed in one pass over the returned flags
        • Routing many keys checks each server's alive? once per call instead of twice per key, and the ring's binary search runs over plain integers
        • Thanks to Julian Richard Contreras for this contribution

      Development:

      • Fix offenses reported by RuboCop 1.91 and require rubocop >= 1.91 (#1162)
        • RuboCop 1.91 adds Style/DirectiveScope; single-statement disable/enable pairs become disable-next directives, which older RuboCop versions do not recognize
        • Removes a misplaced # encoding: ascii comment in client.rb that Ruby had always ignored
      Changelog

      Sourced from dalli's changelog.

      5.1.1

      Security:

      • Fix memcached command injection through numeric arguments (GHSA-6wmv-xq9m-fmp7)
        • The default argument of incr/decr, and fetch_with_lock's lock_ttl and recache_threshold, were written into the meta protocol command without conversion, so a String containing CRLF injected additional memcached commands (e.g. set, flush_all) on the connection
        • These arguments must now be Integers, or Strings of decimal digits; anything else raises ArgumentError before a request is sent
        • As defense in depth, RequestFormatter now converts every numeric flag it writes (D, J, N, R, T) to an Integer
        • Affects 3.2.0 and later (3.2.x only with protocol: :meta); fixed in 5.1.1 and 4.3.4
        • Thanks to oss-security-shop for the report

      Performance:

      • Reduce Ruby overhead on the single-key get path by about 28% (#1160)
        • A plain get builds its mg request with one string interpolation instead of going through meta_get's keyword arguments, and skips option handling when called without options
        • A VA <size> f<flags> hit line is parsed in place instead of being split into tokens
        • The key check for control characters and whitespace uses a byte class that matches the same ASCII bytes as [\p{Cntrl}\s], about 5x faster; this applies to every operation that sends a key
        • Allocations per get hit drop from 23 to 16
        • Thanks to Julian Richard Contreras for this contribution
      • Speed up multi-server get_multi by about 30% (4 servers, 100 keys), and bring small batches in line with 2.7.11 (#1161)
        • Each server's queries and terminating noop are sent before the next server's are built, so memcached answers earlier servers while later ones are prepared
        • A server's queries are built in one pass with RequestFormatter.multi_meta_get, and plain get_multi no longer requests the CAS value it discards (get_multi_cas still does)
        • Pipelined replies are parsed in one pass over the returned flags
        • Routing many keys checks each server's alive? once per call instead of twice per key, and the ring's binary search runs over plain integers
        • Thanks to Julian Richard Contreras for this contribution

      Development:

      • Fix offenses reported by RuboCop 1.91 and require rubocop >= 1.91 (#1162)
        • RuboCop 1.91 adds Style/DirectiveScope; single-statement disable/enable pairs become disable-next directives, which older RuboCop versions do not recognize
        • Removes a misplaced # encoding: ascii comment in client.rb that Ruby had always ignored
      Commits
      • 7bd7daf Merge commit from fork
      • e3b73f6 Prepare 5.1.1 release
      • 5d6b470 Reject non-integer numeric flags in meta protocol commands
      • 473932d Merge pull request #1163 from petergoldstein/docs/changelog-1160-1161-1162
      • 4c20d0c Update CHANGELOG for #1160, #1161 and #1162
      • a2dac30 Merge pull request #1161 from radixdev/perf/faster-multi-server-get-multi
      • dd81192 Add PR number to changelog entry
      • 7b974e5 Speed up multi-server get_multi
      • 3c6e9c6 Merge pull request #1160 from radixdev/perf/faster-single-get
      • 758d1b9 Treat false options like nil on the get fast path
      • Additional commits viewable in compare view

      Updates `aws-sdk-s3` from 1.232.1 to 1.232.2
      Changelog

      Sourced from aws-sdk-s3's changelog.

      1.232.2 (2026-09-25)

      • Issue - Ensure the internally-created executor is shutdown on error in TransferManager and Aws::S3::Object resource methods, preventing leaked worker threads on multipart transfer failures (#3419).
      Commits

      Updates `herb` from 0.10.4 to 0.11.0
      Release notes

      Sourced from herb's releases.

      v0.11.0

      Herb v0.11

      Herb v0.11 ships alongside ReActionView v0.6. Check out the "What's new in Herb v0.11" post on the Herb Blog.

      Parser