I've released a fork of this gem updated to use omniauth 2.0.0 due to this CVE:
Name: omniauth
Version: 1.9.1
CVE: CVE-2015-9284
Criticality: High
URL: https://github.com/omniauth/omniauth/wiki/Resolving-CVE-2015-9284
Title: CSRF vulnerability in OmniAuth's request phase
Solution: upgrade to >= 2.0.0
https://github.com/andyw8/omniauth-pocket-oauth2
@leppert I know this repo hasn't had updates in a long time, but I can create a PR to add these changes here if you wish.
I've released a fork of this gem updated to use omniauth 2.0.0 due to this CVE:
https://github.com/andyw8/omniauth-pocket-oauth2
@leppert I know this repo hasn't had updates in a long time, but I can create a PR to add these changes here if you wish.