Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jun 16, 2022

Bumps guardian from 2.0.0 to 2.2.4.

Release notes

Sourced from guardian's releases.

v2.2.4

What's Changed

New Contributors

Full Changelog: ueberauth/guardian@v2.2.3...v2.2.4

v2.2.3

What's Changed

Full Changelog: ueberauth/guardian@v2.2.2...v2.2.3

v2.2.2

What's Changed

New Contributors

Full Changelog: ueberauth/guardian@v2.2.1...v2.2.2

v2.2.1

No release notes provided.

v2.1.2

see the changelog

v2.1.1

Documentation update

2.1.0

Enhancements:

  • Add option halt to all plugs. This allows to optionally not halt the connection on error so downstream plugs are still called #617
  • Added SlidingCookie plug that allows auto-refreshing cookie tokens #616
  • Documentation updates

... (truncated)

Changelog

Sourced from guardian's changelog.

v2.2.4

Enhancement

  • Check float values of time in time_within_drift?/2.

v2.2.3

Enhancement

  • Ensure that badly-formatted tokens don't raise an exception when attempting to decode them.

v2.2.2

Enhancement

  • Guardian.Plug.EnsureAuthenticated will now accept atom keys in the map passed to the claims option.

v2.2.1

Enhancement

  • Guardian.Plug.VerifyHeader and Guardian.Plug.VerifySession :refresh_from_cookie option will try refreshing when access token not found, invalid or expired if cookie present #683

v2.2.0

Enhancement

  • Add :scheme option to Guardian.Plug.VerifyHeader #680
  • Add :refresh_from_cookie option to Guardian.Plug.VerifyHeader and Guardian.Plug.VerifySession to replace Guardian.Plug.VerifyCookie plug #675

Deprecation

  • :realm option configuration of Guardian.Plug.VerifyHeader is deprecated please use :scheme instead.
  • Guardian.Plug.VerifyCookie is deprecated in favor of :refresh_from_cookie option in Guardian.Plug.VerifyHeader and Guardian.Plug.VerifySession

v2.1.2

Enhancement

  • Documentation improvements
  • Parse the kid from the signing secret to the signature #654

Bugfix

  • Fixed issue with remember_me plug not using the correct ttl #649
  • Fixed failing compilation if plug was not included as a dep #633

... (truncated)

Commits
  • 3f178c4 Check float values of time in time_within_drift?/2 (#700)
  • e369d58 chore: fix readme badge (#698)
  • 09690cd Ensure that badly-formatted tokens don't raise an exception (#697)
  • 49702bc Permit atom keys when verifying claims with EnsureAuthenticated (#696)
  • 882c90b Minor docs improvements, mostly around Verify* plugs (#692)
  • e52a74e Fix markdown syntax errors and typos (#695)
  • a2b93e8 Fix typo in permission docs (#693)
  • 77aa5e7 Corrects Plug.Verify presentation on pipelines.md (#688)
  • 23284f7 Fix typos (#687)
  • 79699fb chore: add release workflow
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [guardian](https://github.com/ueberauth/guardian) from 2.0.0 to 2.2.4.
- [Release notes](https://github.com/ueberauth/guardian/releases)
- [Changelog](https://github.com/ueberauth/guardian/blob/master/CHANGELOG.md)
- [Commits](ueberauth/guardian@v2.0.0...v2.2.4)

---
updated-dependencies:
- dependency-name: guardian
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Jun 16, 2022
@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Sep 2, 2022

Superseded by #388.

@dependabot dependabot bot closed this Sep 2, 2022
@dependabot dependabot bot deleted the dependabot/hex/guardian-2.2.4 branch September 2, 2022 04:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant