mirror of https://github.com/docusealco/docuseal
You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
master
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.10
1.1.11
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
${ noResults }
Adds a JWT-authenticated entry point so the embedding app can mount <docuseal-builder data-token="…"> without the host pre-establishing a DocuSeal session via cross-origin cookies + an external auth gate. - EmbedBuilderController (GET /embed/builder?token=…): verifies a short-lived HS256 JWT against the owner account's API access token (the same key the JSON API uses; raw value is recoverable via the encrypted `token` column), signs that user in (a first-party session inside the iframe), records a template-scoped grant in the session, and redirects into the regular builder — /templates/:id/edit for an existing template, or /new?url=… to download + create from `document_urls`. Requires `exp` and caps token lifetime (replay bound). Only opens template_ids the account owns. - EmbedScoped concern: confines an embed session to its own template (by id, or by external_id for the /new→create→edit redirect) plus the create + builder-support paths; refuses enumeration / other templates / the JSON template API. Fails closed. Path rules mirror the allow-list the host app enforced at the edge, so the builder keeps working while the cross-origin cookie + gate machinery on the host side can be removed. - builder.js shim now iframes /embed/builder?token=… (the server decides edit vs. new) instead of a bare authenticated /new that 404s without a pre-set session cookie. - Request specs for token verification, ownership, exp/lifetime, and scope. |
2 months ago | |
|---|---|---|
| .. | ||
| embed_scoped.rb | Token-authenticated embedded builder (no cross-origin cookies) | 2 months ago |