Upgrade to Pro — share decks privately, control downloads, hide ads and more …

久々にコードを書いてOmniauthでハマった話

 久々にコードを書いてOmniauthでハマった話

Fukuoka.rb 200回 LT大会 (#202)
https://fukuokarb.connpass.com/event/206956/

Avatar for Hiroaki Ninomiya

Hiroaki Ninomiya

March 24, 2021
Tweet

More Decks by Hiroaki Ninomiya

Other Decks in Programming

Transcript

  1. ٕज़ελοΫ • ϑϩϯτ(LIFFΞϓϦ): Vue CLI (webpackerෆ࢖༻) • Next.js on Vercel

    • αʔό: Rails 6.1.3 (Ruby 3.0) on Heroku • omniauth • administrate • ridgepole • crono_trigger
  2. ٕज़ελοΫ • ϑϩϯτ(LIFFΞϓϦ): Vue CLI (webpackerෆ࢖༻) • Next.js on Vercel

    • αʔό: Rails 6.1.3 (Ruby 3.0) on Heroku • omniauth • administrate • ridgepole • crono_trigger
  3. omniauth • ϚϧνϓϩόΠμͷೝূΛఏڙ͢Δgem • ʮSNSϩάΠϯʯΛ࣮૷͢Δͷʹྑ͘࢖ΘΕΔΠϝʔδ • ࣮૷ʹ͸ར༻͍ͨ͠ϓϩόΠμ޲͚ͷϓϥάΠϯ͕ඞཁ • omniauth-twitter΍omniauth-githubͳͲ •

    ؅ཧը໘ͷ؆қϩάΠϯػೳͷͨΊʹ࠾༻ • LINEͷϛχΞϓϦͳͷͰLINEͱ਌࿨ੑ͕ߴ͍ • omniauth-line ͱҰॹʹಋೖͯ͠LINEϩάΠϯ࣮૷ͩʂ
  4. ḷΓண͍ͨͷ͸ • omniauthͷ࢓༷มߋ • 2019೥ࠒͷมߋͰͨ͠ɻࣗ෼ͷແ஌͞Α…… • എܠ: ੬ऑੑCVE-2015-9284 ରԠΒ͍͠ •

    CSRF͞ΕΔϦεΫ͕͋ΔΑ • GETͰ͍͚Δ͔Βҙਤ͠ͳ͍ϩάΠϯͤ͞ΒΕΔΑͶ(ͱ͍͏ཧղ) • ੬ऑੑ͔ͩΒରԠͨ͠ํ͕ྑ͍ • ͪΐͬͱ௚ͤ͹ྑ͍ͷͰ͸ͳ͘ɺ஍ຯʹରԠ͕໘౗