Skip to content

Conversation

@Nateowami
Copy link
Collaborator

@Nateowami Nateowami commented Jan 6, 2026

GetAuthOptions had a return type of PublicAuthOptions, but was returning all auth options (since AuthOptions extends PublicAuthOptions, the types are compatible). In practice this doesn't leak anything to the Razor pages unless the object is serialized, but since the entire purpose of PublicAuthOptions is to limit what is provided to the Razor pages, it seems more complete to not even allow the secrets to be available in the scope of the templates.

@pmachapman What do you think? Too pedantic, or reasonable change?


This change is Reviewable

GetAuthOptions had a return type of PublicAuthOptions, but was returning
all auth options (since AuthOptions extends PublicAuthOptions, the types
are compatible). In practice this doesn't leak anything to the Razor
pages unless the object is serialized, but since the entire purpose of
PublicAuthOptions is to limit what is provided to the Razor pages, it
seems more complete to not even allow the secrets to be available in the
scope of the templates.
@codecov
Copy link

codecov bot commented Jan 6, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 82.82%. Comparing base (dd2b2cb) to head (45f5899).
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@           Coverage Diff           @@
##           master    #3623   +/-   ##
=======================================
  Coverage   82.82%   82.82%           
=======================================
  Files         610      610           
  Lines       37414    37420    +6     
  Branches     6152     6128   -24     
=======================================
+ Hits        30987    30993    +6     
  Misses       5494     5494           
  Partials      933      933           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@pmachapman pmachapman self-assigned this Jan 6, 2026
Copy link
Collaborator

@pmachapman pmachapman left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It would only leak if you recast the object as as AuthOptions, then serialized. Razor pages are generated on the server-side, so it would have to be a very conscious effort of the programmer. I don't see the harm in your approach, though, so :lgtm:

@pmachapman reviewed 1 file and all commit messages, and made 1 comment.
Reviewable status: :shipit: complete! all files reviewed, all discussions resolved (waiting on @Nateowami).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants