You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
OAuth login: state storage and account linking #28
OAuth login cannot complete as wired by the plugin. Authlib keeps the state (anti-CSRF), nonce and PKCE verifier in request.session, which needs Starlette's SessionMiddleware; nothing in enlace_auth installs one (and enlace's diagnose flags SessionMiddleware as critical for apps). The existing tests mock both authorize_redirect and authorize_access_token, so they never exercise the state check. Plan: keep the OAuth state in a small signed cookie scoped to /auth (reusing signing_key, SameSite=Lax) or a server-side store, and add one test that runs the real Authlib state/ID-token path against a stub provider.
An OAuth identity is linked to an existing password account by email alone, with no record of the link. Even with OAuth login: refuse emails the provider marks unverified #27, every account's security is then that of the weakest configured provider. Plan: when the account has a password_hash and no link to this provider, refuse (or require the password once) and record oauth_links: {provider: sub}; match later logins by the provider's stable subject (sub, or oid+tid for Microsoft), not by email.
No login providers are configured on the live platform today, so neither is exposed there.
Found while reviewing #27 (not caused by it):
state(anti-CSRF), nonce and PKCE verifier inrequest.session, which needs Starlette'sSessionMiddleware; nothing in enlace_auth installs one (and enlace's diagnose flagsSessionMiddlewareas critical for apps). The existing tests mock bothauthorize_redirectandauthorize_access_token, so they never exercise the state check. Plan: keep the OAuth state in a small signed cookie scoped to/auth(reusingsigning_key,SameSite=Lax) or a server-side store, and add one test that runs the real Authlib state/ID-token path against a stub provider.password_hashand no link to this provider, refuse (or require the password once) and recordoauth_links: {provider: sub}; match later logins by the provider's stable subject (sub, oroid+tidfor Microsoft), not by email.No login providers are configured on the live platform today, so neither is exposed there.
🤖 Generated with Claude Code