Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Allow newest oauth2 client with security fixes #68

Merged
merged 3 commits into from
Aug 21, 2019

Conversation

PragTob
Copy link
Contributor

@PragTob PragTob commented Aug 21, 2019

oauth2 has a recent possibly backwards incompatible release that
makes sure the spec is followed and authorization headers are
respected (https://github.com/scrogson/oauth2/blob/master/CHANGELOG.md#v200-2019-07-15)
This fixed ueberauth/oauth2#128 hence I think it's important to
include.
Decided to not require 2.x as that might conflict too hard
with other libraries. Also decided to allow minor version bumps
as @scrogson seems to be good about semver <3
As #66 isn't merged yet I'd like it if this could get in with the
release.

fixes #67

oauth2 has a recent possibly backwards incompatible release that
makes sure the spec is followed and authorization headers are
respected (https://github.com/scrogson/oauth2/blob/master/CHANGELOG.md#v200-2019-07-15)
This fixed ueberauth/oauth2#128 hence I think it's important to
include.
Decided to not require 2.x as that might conflict too hard
with other libraries. Also decided to allow minor version bumps
as @scrogson seems to be good about semver <3
As ueberauth#66 isn't merged yet I'd like it if this could get in with the
release.

fixes ueberauth#67
@PragTob
Copy link
Contributor Author

PragTob commented Aug 21, 2019

Failures look like travis can't find their own erlang packages :(

@PragTob
Copy link
Contributor Author

PragTob commented Aug 21, 2019

(I don't have the rights to rerun CI here, hence I pushed an empty commit. I recommend squashing)

@PragTob
Copy link
Contributor Author

PragTob commented Aug 21, 2019

This was also failing on master 17 days ago it seems... I'll remove the old elixir versions and add new ones

@yordis yordis merged commit 76577e2 into ueberauth:master Aug 21, 2019
@PragTob PragTob deleted the allow-newest-oauth2 branch August 21, 2019 19:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Upgrade/allow oauth2 to be 2.0 authorization_code strategy is not authenticated
3 participants