Changes for version 0.10

  • Call env_proxy by default on internal LWP::UserAgent instances to respect standard proxy environment variables (HTTPS_PROXY, NO_PROXY, etc.).
  • Hardened Pluggable credential execution against command injection (CWE-78, CWE-77, CWE-88) and untrusted search paths (CWE-426) by using Text::ParseWords and indirect system execution.
  • Removed insecure blind de-tainting in Pluggable credentials (CWE-184).

Modules

Environment variables used by Google::Auth
Exceptions used in the Google::Auth package

Provides

in lib/Google/Auth/ClientId.pm
in lib/Google/Auth/CloudSDK.pm
in lib/Google/Auth/ComputeEngine.pm
in lib/Google/Auth/Credentials.pm
in lib/Google/Auth/DefaultCredentials.pm
in lib/Google/Auth/Exceptions.pm
in lib/Google/Auth/Exceptions.pm
in lib/Google/Auth/ExternalAccountCredentials.pm
in lib/Google/Auth/ExternalAccountCredentials/Aws.pm
in lib/Google/Auth/ExternalAccountCredentials/Pluggable.pm
in lib/Google/Auth/IAMCredentials.pm
in lib/Google/Auth/IDTokens.pm
in lib/Google/Auth/IDTokens/KeySources.pm
in lib/Google/Auth/IDTokens/KeySources.pm
in lib/Google/Auth/IDTokens/KeySources.pm
in lib/Google/Auth/IDTokens/KeySources.pm
in lib/Google/Auth/IDTokens/KeySources.pm
in lib/Google/Auth/IDTokens/KeySources.pm
in lib/Google/Auth/IDTokens/Verifier.pm
in lib/Google/Auth/IDTokens/KeySources.pm
in lib/Google/Auth/ImpersonatedServiceAccountCredentials.pm
in lib/Google/Auth/Exceptions.pm
in lib/Google/Auth/RetryHelper.pm
in lib/Google/Auth/ServiceAccountCredentials.pm
in lib/Google/Auth/Signet.pm
in lib/Google/Auth/Signet.pm
in lib/Google/Auth/Exceptions.pm
in lib/Google/Auth/UserAuthorizer.pm
in lib/Google/Auth/UserRefreshCredentials.pm
in lib/Google/Auth/WebUserAuthorizer.pm
in lib/Google/Auth/WebUserAuthorizer.pm