mirror of https://github.com/docusealco/docuseal
master
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.10
1.1.11
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
${ noResults }
2 Commits (ff567ee260ddf821a89349b384586d12dab2c474)
| Author | SHA1 | Message | Date |
|---|---|---|---|
|
|
1269391f4c |
Spec fixtures + Time.current; embed builder specs green
- Eager account user so Account#default_template_folder can pick an author. - Pass author: in template fixtures; create the foreign account's user. - Positive scope control tolerates the missing webpack manifest (reaching the view proves the guard allowed the in-scope template). - Time.current over Time.now (Rails/TimeZone). |
2 months ago |
|
|
3c05712819 |
Token-authenticated embedded builder (no cross-origin cookies)
Adds a JWT-authenticated entry point so the embedding app can mount <docuseal-builder data-token="…"> without the host pre-establishing a DocuSeal session via cross-origin cookies + an external auth gate. - EmbedBuilderController (GET /embed/builder?token=…): verifies a short-lived HS256 JWT against the owner account's API access token (the same key the JSON API uses; raw value is recoverable via the encrypted `token` column), signs that user in (a first-party session inside the iframe), records a template-scoped grant in the session, and redirects into the regular builder — /templates/:id/edit for an existing template, or /new?url=… to download + create from `document_urls`. Requires `exp` and caps token lifetime (replay bound). Only opens template_ids the account owns. - EmbedScoped concern: confines an embed session to its own template (by id, or by external_id for the /new→create→edit redirect) plus the create + builder-support paths; refuses enumeration / other templates / the JSON template API. Fails closed. Path rules mirror the allow-list the host app enforced at the edge, so the builder keeps working while the cross-origin cookie + gate machinery on the host side can be removed. - builder.js shim now iframes /embed/builder?token=… (the server decides edit vs. new) instead of a bare authenticated /new that 404s without a pre-set session cookie. - Request specs for token verification, ownership, exp/lifetime, and scope. |
2 months ago |