Skip to content

Tags: rameerez/api_keys

Tags

v0.5.0

Toggle v0.5.0's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
Request restrictions: lock keys to web origins and IP ranges (0.5.0)

Per-key request restrictions enforced inside authentication itself: allowed_origins (exact hosts + *.subdomain wildcards, Origin header with Referer fallback) and allowed_ips (IPv4/IPv6, exact or CIDR). Malformed stored policy fails closed with 403 restriction_misconfigured. Key-type ceilings, config.client_ip_resolver, dashboard fields, generators, and the public/revocable decoupling: public key types now rotate, revoke, and expire like any credential.

Every identified-but-refused request names its key in the after_authentication callback context. Full adversarial review pass included: fail-open shapes, Origin: null precedence, shallow-freeze mutability, and coverage gates all fixed.

454 tests / 1,496 assertions green across the Rails 7.2 / 8.0 / 8.1 x Ruby 3.3 / 3.4 / 4.0 matrix.

v0.4.3

Toggle v0.4.3's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
Bump version to 0.4.3 (clean republish of 0.4.2) (#36)

v0.4.2

Toggle v0.4.2's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
Bump version to 0.4.2 (#34)

v0.4.1

Toggle v0.4.1's commit message
Bump version to 0.4.1

v0.4.0

Toggle v0.4.0's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
Release api_keys 0.4.0 security hardening (#23)

* Prepare v0.4.0 security hardening release

Promote the completed hardening work from Unreleased, document downstream migration and compatibility requirements, and update tracked path-gem metadata.

* Resolve every v0.3 release-review finding

Close every finding tracked in issue #12 with code, regression tests, bounded behavior, or a superseding hardening control. Encrypt and expire session token handoffs, return 403 for missing scope, honor parent_controller, debounce stats jobs, cascade owner deletion, remove redundant indexes and development package files, and document each upgrade consequence. Preserve the already-landed indexed and bounded bcrypt lookup, dynamic job queues, tenant/owner separation, serialized quota creation, safe logging, and raised coverage. Remove the Claude workflow and its unnecessary third-party CI surface.

Validated across the default suite and Rails 7.2, 8.0, and 8.1 appraisals, plus dependency audits, Brakeman, real Rails token encryption, eager loading, production boot, asset compilation, package inspection, and isolated package loading.

v0.3.0

Toggle v0.3.0's commit message
Bump version to 0.3.0

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

v0.2.1

Toggle v0.2.1's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
Merge pull request #4 from rameerez/claude/issue-2-20250804-2224

Fix SecurityController callback reference (v0.2.1)

v0.2.0

Toggle v0.2.0's commit message
Version bump, write Changelog

v0.1.0

Toggle v0.1.0's commit message
Update Gemspec