mirror of https://github.com/docusealco/docuseal
master
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.10
1.1.11
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
${ noResults }
2 Commits (dfc12095ffbd8dd7b988914ac3da10f5d016f015)
| Author | SHA1 | Message | Date |
|---|---|---|---|
|
|
b2d7199756 |
EmbedScoped: allow /embed/builder re-entry with a pinned scope
EmbedBuilderController is the JWT re-entry point but runs behind EmbedScoped's enforce_embed_scope! before_action. Once a prior open pins an embed_scope into the session cookie, re-opening the builder (the same template again, or a different one) hit `head :forbidden` because /embed/builder was not in UNSCOPED_ALLOW — the concern locked out its own re-entry endpoint. First open worked; every reopen 403'd. The token, not the session, authenticates /embed/builder, so always let it through; EmbedBuilderController then overwrites the scope from the fresh token. Add a request spec covering the re-entry/re-scope case. |
2 months ago |
|
|
3c05712819 |
Token-authenticated embedded builder (no cross-origin cookies)
Adds a JWT-authenticated entry point so the embedding app can mount <docuseal-builder data-token="…"> without the host pre-establishing a DocuSeal session via cross-origin cookies + an external auth gate. - EmbedBuilderController (GET /embed/builder?token=…): verifies a short-lived HS256 JWT against the owner account's API access token (the same key the JSON API uses; raw value is recoverable via the encrypted `token` column), signs that user in (a first-party session inside the iframe), records a template-scoped grant in the session, and redirects into the regular builder — /templates/:id/edit for an existing template, or /new?url=… to download + create from `document_urls`. Requires `exp` and caps token lifetime (replay bound). Only opens template_ids the account owns. - EmbedScoped concern: confines an embed session to its own template (by id, or by external_id for the /new→create→edit redirect) plus the create + builder-support paths; refuses enumeration / other templates / the JSON template API. Fails closed. Path rules mirror the allow-list the host app enforced at the edge, so the builder keeps working while the cross-origin cookie + gate machinery on the host side can be removed. - builder.js shim now iframes /embed/builder?token=… (the server decides edit vs. new) instead of a bare authenticated /new that 404s without a pre-set session cookie. - Request specs for token verification, ownership, exp/lifetime, and scope. |
2 months ago |