v2.3.4
2.3.4 - 2026-05-18
- TAG: v2.3.4
- COVERAGE: 97.44% -- 304/312 lines in 4 files
- BRANCH COVERAGE: 79.58% -- 113/142 branches in 4 files
- 94.44% documented
Added
- Add
header_auth_sourceto require explicit selection of trusted header identity source (:envor:http_header) - Add
header_auth_require_tlsto require TLS for trusted header SSO by default - Log a prominent security warning when
header_authis enabled
Changed
- Trusted header SSO now defaults to trusting only server-set env variables and no longer checks Rack
HTTP_header variants unlessheader_auth_source: :http_headeris configured
Fixed
- Fix OpenSSL 3/Ruby 4 compatibility in the TLS options adaptor spec
Security
- Harden trusted header SSO against spoofing by removing automatic fallback from
REMOTE_USERtoHTTP_REMOTE_USER
Many paths lead to being a sponsor or a backer of this project. Are you on such a path?