Current issue state, recent activity, and per-issue timelines from the indexed issue data.
| Date | Opened | Closed | Comments | Events | Open Backlog |
|---|---|---|---|---|---|
| 2026-09-13 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-12 | 0 | 0 | 0 | 0 | 12 |
| 2026-09-11 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-10 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-09 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-08 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-07 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-06 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-05 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-04 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-03 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-02 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-01 | 0 | 0 | 0 | 0 | 0 |
| 2026-08-31 | 0 | 0 | 0 | 0 | 0 |
Opened: 0
Closed: 0
Comments: 0
Events: 0
| Issue | Author | State | Labels | Comments | Reactions | Updated |
|---|---|---|---|---|---|---|
#1719 Refresh Tokens as-implemented are susceptible to Refresh Token Reuse Attacks Opened 2 years ago | ThisIsMissEm | open | No labels | 3 | 2 | 2 days ago |
#1730 There is no way to refresh an access token without revoking the previous access token Opened 2 years ago | ransombriggs | open | No labels | 4 | 3 | 2 days ago |
#1892 Deprecation or removal of insecure grant flows Opened 1 month ago | ThisIsMissEm | open | No labels | 0 | 0 | 2 days ago |
#1771 Refresh tokens cannot reduce scopes correctly Opened 1 year ago | ThisIsMissEm | open | No labels | 3 | 0 | 2 days ago |
#1875 Client ID Metadata Documents (CIMDs) Opened 2 months ago | ThisIsMissEm | open | No labels | 6 | 6 | 2 days ago |
#1675 Better support for credential rotation Opened 3 years ago | sgallag-insta | open | feature request | 2 | 4 | 2 days ago |
#1768 Support OAuth RFC - JWT for Client Authentication and Authorization Grants Opened 1 year ago | hagaivcita | open | No labels | 11 | 0 | 8 days ago |
#1711 Doorkeeper appears to be missing a way to validate client configuration before redirecting to the authentication page Opened 2 years ago | ransombriggs | closed - completed | No labels | 2 | 0 | 23 days ago |
#1914 IP address pinning after DNS resolution happens before vetting that the IP address works Opened 25 days ago | supersam654 | open | No labels | 1 | 1 | 24 days ago |
#1600 Is there a way to store Doorkeeper::AccessToken data inside Doorkeeper::JWT (and not use db-backed tokens)? Opened 4 years ago | NeilSlater-Clixifix | open | feature request | 7 | 0 | 26 days ago |
#1613 Currently signed in user can revoke other users tokens Opened 4 years ago | sofianegargouri | closed - completed | bug? security | 5 | 0 | 27 days ago |
#1580 With enable_application_owner, issuing a token with grant_type=client_credentials does not associate the token with the owner Opened 4 years ago | Oromis | closed - completed | bug? pinned | 12 | 1 | 27 days ago |
#1911 Improving publishing security? Opened 1 month ago | ThisIsMissEm | open | No labels | 4 | 2 | 29 days ago |
#1799 Feature request: Support Identity Assertion JWT Authorization Grant (ID-JAG) Opened 6 months ago | Akankshabhasin | closed - completed | No labels | 4 | 0 | 1 month ago |
#1908 Missing documentation about doorkeeper:db:cleanup Opened 1 month ago | Kulgar | closed - completed | No labels | 5 | 1 | 1 month ago |
#1889 Default-scope calculation diverges between the authorization and token endpoints when dynamic scopes are enabled Opened 1 month ago | 55728 | closed - completed | No labels | 0 | 0 | 1 month ago |
#1873 `force_pkce` requires a `code_challenge` from response types that never issue an authorization code Opened 2 months ago | 55728 | closed - completed | No labels | 3 | 0 | 1 month ago |
#1554 Response header too long for default nginx configuration Opened 5 years ago | Gargron | closed - completed | wontfix | 15 | 2 | 1 month ago |
#1764 Issue: Configuring Active Record to Use Different Base Classes for Sharded and Non-Sharded Models Opened 2 years ago | rishav-enigma | closed - completed | No labels | 1 | 0 | 1 month ago |
#1787 Refresh Token Rotation + Expiry questions Opened 9 months ago | stevetsanders | closed - completed | No labels | 3 | 0 | 1 month ago |
#1756 How to implement using multi-database like Makara Opened 2 years ago | benviloria | closed - completed | No labels | 1 | 0 | 1 month ago |
#1759 Introspecting a token should behave the same wrt "revoke on use" Opened 2 years ago | kmayer | closed - completed | No labels | 1 | 0 | 1 month ago |
#984 Is there Digest support for Doorkeeper Client Credentials Authentication Opened 9 years ago | jaluke | closed - completed | question/discussion enhancement RFC | 6 | 0 | 1 month ago |
#1291 Add IndieAuth support Opened 7 years ago | BenLubar | closed - completed | feature request pinned | 9 | 2 | 1 month ago |
#1663 reuse_access_token config should be used when refreshing a token Opened 3 years ago | PhilippeChab | closed - completed | No labels | 7 | 4 | 1 month ago |