Skip to content

v0.3.0 — security release

Latest

Choose a tag to compare

@stevegeek stevegeek released this 02 May 18:48
· 1 commit to main since this release

Security release. Shared version bump across all four gems per the monorepo convention; only another_api has functional changes — the other three (api_serializer, api_query_language, api_query_language-active_record) are no-op releases.

Security

  • another_api — AnotherApi::Configuration#token_model is now resolved to a class once via safe_constantize, validated to respond to .find_by_token, and memoised. Authentication uses the memoised class, so mutating AnotherApi.configuration.token_model after boot can no longer redirect authentication to a different class. validate! forces resolution eagerly so misconfiguration fails at boot.
  • another_api — ParamDeserializer no longer merges the entire request body into deserializer input. Input is sliced to keys declared on the schema, and attributes flagged virtual: true are excluded — they are computed server-side and accepting them from request params was a mass-assignment vector. Explicit from: remaps are honoured (top-level segment of from_path).

Changed

  • another_api — ParamDeserializer#deserialize_params now silently drops keys outside the schema's declared input. Previously any key in the request body was passed through to the transformer. Callers that relied on extra keys leaking through must declare them on the deserializer.

Full changelog: v0.2.0...v0.3.0