Tags: rameerez/api_keys
Tags
Request restrictions: lock keys to web origins and IP ranges (0.5.0) Per-key request restrictions enforced inside authentication itself: allowed_origins (exact hosts + *.subdomain wildcards, Origin header with Referer fallback) and allowed_ips (IPv4/IPv6, exact or CIDR). Malformed stored policy fails closed with 403 restriction_misconfigured. Key-type ceilings, config.client_ip_resolver, dashboard fields, generators, and the public/revocable decoupling: public key types now rotate, revoke, and expire like any credential. Every identified-but-refused request names its key in the after_authentication callback context. Full adversarial review pass included: fail-open shapes, Origin: null precedence, shallow-freeze mutability, and coverage gates all fixed. 454 tests / 1,496 assertions green across the Rails 7.2 / 8.0 / 8.1 x Ruby 3.3 / 3.4 / 4.0 matrix.
Release api_keys 0.4.0 security hardening (#23) * Prepare v0.4.0 security hardening release Promote the completed hardening work from Unreleased, document downstream migration and compatibility requirements, and update tracked path-gem metadata. * Resolve every v0.3 release-review finding Close every finding tracked in issue #12 with code, regression tests, bounded behavior, or a superseding hardening control. Encrypt and expire session token handoffs, return 403 for missing scope, honor parent_controller, debounce stats jobs, cascade owner deletion, remove redundant indexes and development package files, and document each upgrade consequence. Preserve the already-landed indexed and bounded bcrypt lookup, dynamic job queues, tenant/owner separation, serialized quota creation, safe logging, and raised coverage. Remove the Claude workflow and its unnecessary third-party CI surface. Validated across the default suite and Rails 7.2, 8.0, and 8.1 appraisals, plus dependency audits, Brakeman, real Rails token encryption, eager loading, production boot, asset compilation, package inspection, and isolated package loading.