Skip to content

v2.3.4

Choose a tag to compare

@pboling pboling released this 18 May 08:08
· 57 commits to main since this release
v2.3.4
d831e0f

2.3.4 - 2026-05-18

  • TAG: v2.3.4
  • COVERAGE: 97.44% -- 304/312 lines in 4 files
  • BRANCH COVERAGE: 79.58% -- 113/142 branches in 4 files
  • 94.44% documented

Added

  • Add header_auth_source to require explicit selection of trusted header identity source (:env or :http_header)
  • Add header_auth_require_tls to require TLS for trusted header SSO by default
  • Log a prominent security warning when header_auth is enabled

Changed

  • Trusted header SSO now defaults to trusting only server-set env variables and no longer checks Rack HTTP_ header variants unless header_auth_source: :http_header is configured

Fixed

  • Fix OpenSSL 3/Ruby 4 compatibility in the TLS options adaptor spec

Security

  • Harden trusted header SSO against spoofing by removing automatic fallback from REMOTE_USER to HTTP_REMOTE_USER

Official Discord 👉️ Live Chat on Discord

Many paths lead to being a sponsor or a backer of this project. Are you on such a path?

Sponsor Me on Github Liberapay Goal Progress Donate on PayPal

Buy me a coffee Donate on Polar Donate to my FLOSS efforts at ko-fi.com Donate to my FLOSS efforts using Patreon