Skip to content

OAuth login: refuse emails the provider marks unverified - #27

Merged
thorwhalen merged 2 commits into
mainfrom
require-verified-oauth-email
Sep 22, 2026
Merged

thorwhalen merged 2 commits into
mainfrom
require-verified-oauth-email

Conversation

@thorwhalen

@thorwhalen thorwhalen commented Sep 22, 2026 •

Copy link
Copy Markdown
Member

The OAuth login callback (/auth/callback/{provider}, "sign in with Google/GitHub/…") matched or created accounts by the email the provider returned, without looking at the provider's email_verified claim. Accounts are keyed by email, so a provider that returns an unverified address would let someone sign in as the owner of that address — including an existing password account.

  • The callback now requires the provider to affirm the address (email_verified true, boolean or string); otherwise 401, no session.
  • Providers that never send the claim are refused unless they are the github preset (GitHub only exposes verified emails on /user) or configured with the new trust_unverified_email = true (documented: never for Microsoft Entra ID, whose email is tenant-editable).
  • The failure response no longer echoes the exception (it could carry callback parameters); the success body is built with JSONResponse.
  • Behaviour change: a custom OIDC provider that omits email_verified now needs trust_unverified_email. The existing callback test's fake Google payload now includes email_verified: true, as Google's real ID token does.

Independent refute-review done: its blocker (claim omitted → allowed, i.e. Microsoft Entra "nOAuth") and nits are fixed here; two pre-existing issues it found are filed as #28.

Not used by the live platform today (no login providers configured there); library hardening.

Tests: two new cases in tests/test_oauth.py + a doctest; full suite green locally.

🤖 Generated with Claude Code

thorwhalen and others added 2 commits September 22, 2026 15:35
Accounts are keyed by email, so an OIDC userinfo with
email_verified=false would let someone sign in as (or pre-register) the
owner of that address, including an existing password account. Providers
that omit the claim are unaffected.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Providers that never send email_verified (e.g. Microsoft Entra ID, whose
email is tenant-editable) could still sign in as anyone's account. The
callback now requires email_verified true, except for the github preset
(only verified emails on /user) or a provider configured with
trust_unverified_email = true. Also: generic OAuth failure message (the
exception echoed callback parameters) and a JSONResponse body.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@thorwhalen
thorwhalen merged commit ffa7586 into main Sep 22, 2026
12 checks passed
@thorwhalen
thorwhalen deleted the require-verified-oauth-email branch September 22, 2026 15:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant