OAuth login: refuse emails the provider marks unverified - #27
Merged
Merged
Conversation
Accounts are keyed by email, so an OIDC userinfo with email_verified=false would let someone sign in as (or pre-register) the owner of that address, including an existing password account. Providers that omit the claim are unaffected. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Providers that never send email_verified (e.g. Microsoft Entra ID, whose email is tenant-editable) could still sign in as anyone's account. The callback now requires email_verified true, except for the github preset (only verified emails on /user) or a provider configured with trust_unverified_email = true. Also: generic OAuth failure message (the exception echoed callback parameters) and a JSONResponse body. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The OAuth login callback (
/auth/callback/{provider}, "sign in with Google/GitHub/…") matched or created accounts by the email the provider returned, without looking at the provider'semail_verifiedclaim. Accounts are keyed by email, so a provider that returns an unverified address would let someone sign in as the owner of that address — including an existing password account.email_verifiedtrue, boolean or string); otherwise 401, no session.githubpreset (GitHub only exposes verified emails on/user) or configured with the newtrust_unverified_email = true(documented: never for Microsoft Entra ID, whoseemailis tenant-editable).JSONResponse.email_verifiednow needstrust_unverified_email. The existing callback test's fake Google payload now includesemail_verified: true, as Google's real ID token does.Independent refute-review done: its blocker (claim omitted → allowed, i.e. Microsoft Entra "nOAuth") and nits are fixed here; two pre-existing issues it found are filed as #28.
Not used by the live platform today (no login providers configured there); library hardening.
Tests: two new cases in
tests/test_oauth.py+ a doctest; full suite green locally.🤖 Generated with Claude Code