Skip to content

Modernize dependencies, add MIT license, and automate releases - #7

Merged
kfalconer merged 1 commit into
masterfrom
modernize-dependencies
Aug 27, 2026
Merged

kfalconer merged 1 commit into
masterfrom
modernize-dependencies

Conversation

@kfalconer

Copy link
Copy Markdown
Contributor

Brings omniauth-fdc up to the same footing as omniauth-shipbob#11: OmniAuth 2.x, a clean dependency audit, and automated publishing to RubyGems.

Dependencies

omniauth ~> 2.0 + omniauth-oauth2 ~> 1.9 (previously an unpinned omniauth-oauth2, resolving to omniauth 1.9 / oauth2 1.4), Ruby >= 3.2, .ruby-version → 3.4.8. Dev toolchain moves to rspec 3.13, rake 13, rack-test 2.2, webmock 3.25; the bundler ~> 1.16 dev pin is gone.

This is breaking for host applications. They must upgrade to OmniAuth 2.x, and Rails apps also need omniauth-rails_csrf_protection because OmniAuth 2 only accepts POST for the request phase.

Vulnerabilities

bundler-audit against the old lockfile reported 39 advisories; the new one reports 0. Notables: omniauth CVE-2020-36599 (Critical) and CVE-2015-9284, oauth2 CVE-2026-54603, jwt CVE-2026-45363, faraday CVE-2026-54297, and 30 against rack 2.2.3.

Two pins that keep the OAuth exchange working

  • auth_scheme: :request_body. Verified from source that oauth2 1.4.4 defaulted to :request_body and 2.0.25 defaults to :basic_auth — without the pin, client_id/client_secret would move out of the token request body and Fulfillment.com would receive something different.
  • callback_url no longer adds script_name. This is a genuine bug, not a port. omniauth 1.9 excluded SCRIPT_NAME from callback_path; omniauth 2 moved it in, so carrying the old full_host + script_name + callback_path forward double-counts the mount prefix. A test caught it emitting redirect_uri=http://example.org/users/users/auth/fdc/callback. It still drops the query string, which is what added callback url method #4 added the override for.

Note

omniauth-shipbob has the same latent bug — its override is still full_host + script_name + callback_path. It only bites when the strategy is mounted under a SCRIPT_NAME (e.g. Devise's /users), so it may be dormant there. Worth a one-line follow-up.

Publishing

Releases are cut from the GitHub Releases UI: publishing a vX.Y.Z release reruns the full test matrix, refuses to continue if the tag and version.rb disagree, and pushes the gem via RubyGems trusted publishing (OIDC) — no stored API key, and the gemspec keeps rubygems_mfa_required. The trusted publisher and the release environment are already configured.

Travis is replaced by GitHub Actions across Ruby 3.2–3.4. bundle-audit runs on push/PR plus a weekly cron, deliberately in its own workflow so a newly-published advisory cannot block an otherwise-green release.

Also

  • Version 0.1.2 → 0.2.0 (0.1.2 is what's currently live on RubyGems).
  • Default client_options[:site] of https://auth.fulfillment.com, taken from the setup lambdas in dropstream and dropstream-2x which override it with the identical value — so the strategy now works without one.
  • MIT LICENSE.txt, declared in the gemspec; real README.md replacing the TODO template; CHANGELOG.md.
  • Gemspec ships only lib/, README, CHANGELOG, LICENSE and the gemspec itself; bin/ is no longer packaged as gem executables.
  • Fixed bin/console, which required a non-existent omniauth/fdc file.
  • Removed the committed .gem build artifacts, pkg/, and .DS_Store.

Testing

Suite goes from 3 examples to 16, adding integration coverage of the request phase, the token exchange (including credentials-in-body and the absence of a Basic auth fallback), the redirect_uri override, the mount-prefix case, and the auth hash — against both the default and an overridden auth host.

Verified locally on Ruby 3.4.8 and 3.3.5: 16 examples, 0 failures, bundle-audit clean, and rake build produces a gem containing only the intended files.

🤖 Generated with Claude Code

Requires omniauth 2.x, omniauth-oauth2 1.9.x and Ruby >= 3.2, which clears
39 advisories carried by the old locked tree (omniauth CVE-2020-36599 and
CVE-2015-9284, oauth2 CVE-2026-54603, jwt CVE-2026-45363, faraday
CVE-2026-54297, and 30 against rack 2.2.3).

Two pins keep the OAuth exchange behaving as it did:

- auth_scheme is pinned to :request_body. oauth2 1.4 defaulted to that;
  oauth2 2.0 defaults to :basic_auth, which would have moved client_id and
  client_secret out of the token request body.
- callback_url no longer adds script_name. omniauth 1.9 excluded SCRIPT_NAME
  from callback_path, but omniauth 2 moved it in, so the old override would
  have doubled a mount prefix and sent
  redirect_uri=http://host/users/users/auth/fdc/callback. It still drops the
  query string, which is what the override was added for (#4).

Also adds a default client_options[:site] of https://auth.fulfillment.com,
matching what consuming apps set through a setup lambda, so the strategy
works without one.

Releases now come from the GitHub Releases UI: publishing a vX.Y.Z release
reruns the test matrix, checks the tag against version.rb, and publishes to
RubyGems.org via trusted publishing, so no API key is stored and the gemspec
can keep rubygems_mfa_required. Travis is replaced by GitHub Actions across
Ruby 3.2-3.4, plus a weekly bundle-audit run kept in its own workflow so a
new advisory cannot block an otherwise-green release.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@kfalconer
kfalconer merged commit 1ccc5c1 into master Aug 27, 2026
4 checks passed
@kfalconer
kfalconer deleted the modernize-dependencies branch August 27, 2026 11:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant