* WIP: Add credentials using a generic EncryptedConfiguration class This is sketch code so far. * Flesh out EncryptedConfiguration and test it * Better name * Add command and generator for credentials * Use the Pathnames * Extract EncryptedFile from EncryptedConfiguration and add serializers * Test EncryptedFile * Extract serializer validation * Stress the point about losing comments * Allow encrypted configuration to be read without parsing for display * Use credentials by default and base them on the master key * Derive secret_key_base in test/dev, source it from credentials in other envs And document the usage. * Document the new credentials setup * Stop generating the secrets.yml file now that we have credentials * Document what we should have instead Still need to make it happen, tho. * [ci skip] Keep wording to `key base`; prefer defaults. Usually we say we change defaults, not "spec" out a release. Can't use backticks in our sdoc generated documentation either. * Abstract away OpenSSL; prefer MessageEncryptor. * Spare needless new when raising. * Encrypted file test shouldn't depend on subclass. * [ci skip] Some woordings. * Ditch serializer future coding. * I said flip it. Flip it good. * [ci skip] Move require_master_key to the real production.rb. * Add require_master_key to abort the boot process. In case the master key is required in a certain environment we should inspect that the key is there and abort if it isn't. * Print missing key message and exit immediately. Spares us a lengthy backtrace and prevents further execution. I've verified the behavior in a test app, but couldn't figure the test out as loading the app just exits immediately with: ``` /Users/kasperhansen/Documents/code/rails/activesupport/lib/active_support/testing/isolation.rb:23:in `load': marshal data too short (ArgumentError) from /Users/kasperhansen/Documents/code/rails/activesupport/lib/active_support/testing/isolation.rb:23:in `run' from /Users/kasperhansen/.rbenv/versions/2.4.1/lib/ruby/gems/2.4.0/gems/minitest-5.10.2/lib/minitest.rb:830:in `run_one_method' from /Users/kasperhansen/.rbenv/versions/2.4.1/lib/ruby/gems/2.4.0/gems/minitest-5.10.2/lib/minitest/parallel.rb:32:in `block (2 levels) in start' ``` It's likely we need to capture and prevent the exit somehow. Kernel.stub(:exit) didn't work. Leaving it for tomorrow. * Fix require_master_key config test. Loading the app would trigger the `exit 1` per require_master_key's semantics, which then aborted the test. Fork and wait for the child process to finish, then inspect the exit status. Also check we aborted because of a missing master key, so something else didn't just abort the boot. Much <3 to @tenderlove for the tip. * Support reading/writing configs via methods. * Skip needless deep symbolizing. * Remove save; test config reader elsewhere. * Move secret_key_base check to when we're reading it. Otherwise we'll abort too soon since we don't assign the secret_key_base to secrets anymore. * Add missing string literal comments; require unneeded yaml require. * ya ya ya, rubocop. * Add master_key/credentials after bundle. Then we can reuse the existing message on `rails new bc4`. It'll look like: ``` Using web-console 3.5.1 from https://github.com/rails/web-console.git (at master@ce985eb) Using rails 5.2.0.alpha from source at `/Users/kasperhansen/Documents/code/rails` Using sass-rails 5.0.6 Bundle complete! 16 Gemfile dependencies, 72 gems now installed. Use `bundle info [gemname]` to see where a bundled gem is installed. Adding config/master.key to store the master encryption key: 97070158c44b4675b876373a6bc9d5a0 Save this in a password manager your team can access. If you lose the key, no one, including you, can access anything encrypted with it. create config/master.key ``` And that'll be executed even if `--skip-bundle` was passed. * Ensure test app has secret_key_base. * Assign secret_key_base to app or omit. * Merge noise * Split options for dynamic delegation into its own method and use deep symbols to make it work * Update error to point to credentials instead * Appease Rubocop * Validate secret_key_base when reading it. Instead of relying on the validation in key_generator move that into secret_key_base itself. * Fix generator and secrets test. Manually add config.read_encrypted_secrets since it's not there by default anymore. Move mentions of config/secrets.yml to config/credentials.yml.enc. * Remove files I have no idea how they got here. * [ci skip] swap secrets for credentials. * [ci skip] And now, changelogs are coming.
6.3 KiB
-
Add
config/credentials.yml.enc
to store production app secrets.Allows saving any authentication credentials for third party services directly in repo encrypted with
config/master.key
orENV["RAILS_MASTER_KEY"]
.This will eventually replace
Rails.application.secrets
and the encrypted secrets introduced in Rails 5.1.DHH, Kasper Timm Hansen
-
Add
ActiveSupport::EncryptedFile
andActiveSupport::EncryptedConfiguration
.Allows for stashing encrypted files or configuration directly in repo by encrypting it with a key.
Backs the new credentials setup above, but can also be used independently.
DHH, Kasper Timm Hansen
-
Module#delegate_missing_to
now raisesDelegationError
if target is nil, similar toModule#delegate
.Anton Khamets
-
Update
String#camelize
to provide feedback when wrong option is passedString#camelize
was returning nil without any feedback when an invalid option was passed as a parameter.Previously:
'one_two'.camelize(true) => nil
Now:
'one_two'.camelize(true) => ArgumentError: Invalid option, use either :upper or :lower.
Ricardo Díaz
-
Fix modulo operations involving durations
Rails 5.1 introduced
ActiveSupport::Duration::Scalar
as a wrapper around numeric values as a way of ensuring a duration was the outcome of an expression. However, the implementation was missing support for modulo operations. This support has now been added and should result in a duration being returned from expressions involving modulo operations.Prior to Rails 5.1:
5.minutes % 2.minutes => 60
Now:
5.minutes % 2.minutes => 1 minute
Fixes #29603 and #29743.
Sayan Chakraborty, Andrew White
-
Fix division where a duration is the denominator
PR #29163 introduced a change in behavior when a duration was the denominator in a calculation - this was incorrect as dividing by a duration should always return a
Numeric
. The behavior of previous versions of Rails has been restored.Fixes #29592.
Andrew White
-
Add purpose and expiry support to
ActiveSupport::MessageVerifier
&ActiveSupport::MessageEncryptor
.For instance, to ensure a message is only usable for one intended purpose:
token = @verifier.generate("x", purpose: :shipping) @verifier.verified(token, purpose: :shipping) # => "x" @verifier.verified(token) # => nil
Or make it expire after a set time:
@verifier.generate("x", expires_in: 1.month) @verifier.generate("y", expires_at: Time.now.end_of_year)
Showcased with
ActiveSupport::MessageVerifier
, but works the same forActiveSupport::MessageEncryptor
'sencrypt_and_sign
anddecrypt_and_verify
.Pull requests: #29599, #29854
Assain Jaleel
-
Make the order of
Hash#reverse_merge!
consistent withHashWithIndifferentAccess
.Erol Fornoles
-
Add
freeze_time
helper which freezes time toTime.now
in tests.Prathamesh Sonpatki
-
Default
ActiveSupport::MessageEncryptor
to use AES 256 GCM encryption.On for new Rails 5.2 apps. Upgrading apps can find the config as a new framework default.
Assain Jaleel
-
Cache:
write_multi
Rails.cache.write_multi foo: 'bar', baz: 'qux'
Plus faster fetch_multi with stores that implement
write_multi_entries
. Keys that aren't found may be written to the cache store in one shot instead of separate writes.The default implementation simply calls
write_entry
for each entry. Stores may override if they're capable of one-shot bulk writes, like RedisMSET
.Jeremy Daer
-
Add default option to module and class attribute accessors.
mattr_accessor :settings, default: {}
Works for
mattr_reader
,mattr_writer
,cattr_accessor
,cattr_reader
, andcattr_writer
as well.Genadi Samokovarov
-
Add
Date#prev_occurring
andDate#next_occurring
to return specified next/previous occurring day of week.Shota Iguchi
-
Add default option to
class_attribute
.Before:
class_attribute :settings self.settings = {}
Now:
class_attribute :settings, default: {}
DHH
-
#singularize
and#pluralize
now respect uncountables for the specified locale.Eilis Hamilton
-
Add
ActiveSupport::CurrentAttributes
to provide a thread-isolated attributes singleton. Primary use case is keeping all the per-request attributes easily available to the whole system.DHH
-
Fix implicit coercion calculations with scalars and durations
Previously, calculations where the scalar is first would be converted to a duration of seconds, but this causes issues with dates being converted to times, e.g:
Time.zone = "Beijing" # => Asia/Shanghai date = Date.civil(2017, 5, 20) # => Mon, 20 May 2017 2 * 1.day # => 172800 seconds date + 2 * 1.day # => Mon, 22 May 2017 00:00:00 CST +08:00
Now, the
ActiveSupport::Duration::Scalar
calculation methods will try to maintain the part structure of the duration where possible, e.g:Time.zone = "Beijing" # => Asia/Shanghai date = Date.civil(2017, 5, 20) # => Mon, 20 May 2017 2 * 1.day # => 2 days date + 2 * 1.day # => Mon, 22 May 2017
Fixes #29160, #28970.
Andrew White
-
Add support for versioned cache entries. This enables the cache stores to recycle cache keys, greatly saving on storage in cases with frequent churn. Works together with the separation of
#cache_key
and#cache_version
in Active Record and its use in Action Pack's fragment caching.DHH
-
Pass gem name and deprecation horizon to deprecation notifications.
Willem van Bergen
-
Add support for
:offset
and:zone
toActiveSupport::TimeWithZone#change
Andrew White
-
Add support for
:offset
toTime#change
Fixes #28723.
Andrew White
-
Add
fetch_values
forHashWithIndifferentAccess
The method was originally added to
Hash
in Ruby 2.3.0.Josh Pencheon
Please check 5-1-stable for previous changes.