Skip to content

Loosen oauth2 version restriction#15

Open
dchill42 wants to merge 1 commit intoClever:masterfrom
LearnZillion:bump_oauth
Open

Loosen oauth2 version restriction#15
dchill42 wants to merge 1 commit intoClever:masterfrom
LearnZillion:bump_oauth

Conversation

@dchill42
Copy link

@dchill42 dchill42 commented Jan 25, 2024

We need to be able to use omniauth-oauth2 v2.0 in order to resolve CVE-2015-9284.

@dchill42
Copy link
Author

@rgarcia Is there anyone available to review this PR? Is there anything else I need to do to satisfy the PR checks?

@SamuelAierizer
Copy link

@dchill42 - Did you decide to just drop this gem and write your won implementation instead?

@dchill42
Copy link
Author

@SamuelAierizer we ended up using a private fork configured in our Gemfile

@SamuelAierizer
Copy link

@dchill42 - did you also have to modify the endpoints or some other functionality? I know API v.1 has been deprecated.
We use old ruby so the dependency is not an issue but I keep getting invalid_credentials messages from Clever.

@SamuelAierizer
Copy link

@dchill42 - also thank you very much for the quick response! 🫡

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants