Remove predictable ids from OAuth consent form fields
What does this MR do and why
The OAuth authorization consent page (app/views/doorkeeper/authorizations/new.html.haml) rendered its hidden fields with hidden_field_tag, which emits predictable id="client_id", id="redirect_uri", etc. by default. config.action_view.form_with_generates_ids = false only governs the form_with/form_for builders, not the *_tag helpers, so these ids shipped even though the device authorization flow already strips element ids as an anti-phishing hardening (see !4941 (closed), !4563 (merged)).
This converts both the authorize and cancel forms to form_with + f.hidden_field, matching how the device flow (doorkeeper/device_authorization_grant/authorize.html.haml) already builds its form. The builder honours form_with_generates_ids = false, so no predictable element ids reach the DOM without any per-field overrides. It also extends the Secure OAuth Authorizations shared example with a not_to have_css('form [id]') assertion so the consent page is guarded the same way the device pages already are.
How to set up and validate locally
- Run the feature spec:
Expect
bundle exec rspec spec/features/oauth_provider_authorize_spec.rb11 examples, 0 failures. The new no-id assertion fails if the forms revert to a builder/config that generates element ids. - Manually: begin an OAuth authorize flow (e.g.
/oauth/authorize?...), open the consent form in DevTools, and confirm the hidden inputs carrynamebut noidattribute.
Screenshots or screen recordings
N/A - no visible UI change; only DOM id attributes are removed.