Security release. Shared version bump across all four gems per the monorepo convention; only another_api has functional changes — the other three (api_serializer, api_query_language, api_query_language-active_record) are no-op releases.
Security
- another_api —
AnotherApi::Configuration#token_modelis now resolved to a class once viasafe_constantize, validated to respond to.find_by_token, and memoised. Authentication uses the memoised class, so mutatingAnotherApi.configuration.token_modelafter boot can no longer redirect authentication to a different class.validate!forces resolution eagerly so misconfiguration fails at boot. - another_api —
ParamDeserializerno longer merges the entire request body into deserializer input. Input is sliced to keys declared on the schema, and attributes flaggedvirtual: trueare excluded — they are computed server-side and accepting them from request params was a mass-assignment vector. Explicitfrom:remaps are honoured (top-level segment offrom_path).
Changed
- another_api —
ParamDeserializer#deserialize_paramsnow silently drops keys outside the schema's declared input. Previously any key in the request body was passed through to the transformer. Callers that relied on extra keys leaking through must declare them on the deserializer.
Full changelog: v0.2.0...v0.3.0