Skip to content

fix(auth): OAuth 回调 fragment 去凭证化仅保留非敏感状态 - #80

Merged
fxbin merged 3 commits into
mainfrom
issue-63-tokenless-fragment
Sep 27, 2026
Merged

fxbin merged 3 commits into
mainfrom
issue-63-tokenless-fragment

Conversation

@fxbin

@fxbin fxbin commented Sep 27, 2026

Copy link
Copy Markdown
Owner

What & why

修复 #63 / 矩阵 D-6:OAuth 成功回调把完整 access token 放进回跳前端的 URL fragment(oauth.py 的 oauth_callback),对前端 JS、浏览器地址栏与 history 暴露凭证——同响应已下发 HttpOnly cookie,fragment 里的 token 纯属多余暴露面。

  • 后端:fragment 仅携带非敏感状态 provider + expires_at,凭证只经 HttpOnly cookie;
  • 前端(oauth/callback/page.tsx):不再读取任何凭证类 fragment 参数,直接以 cookie 拉 /auth/me 判定登录态;旧版 #token=... 链接仍能落地但一律不消费(兼容行为);
  • 回归转正(矩阵 D-6 要求):GitHub / Google 两条 mock 回归断言 fragment 不含 token=、含 provider 与 expires_at,cookie 照常下发。

Refs #63。Closes #63。

Area

  • auth
  • backend
  • frontend

Verification

  • tests_oauth_patch/ 29 项全绿(含转正的 fragment 无凭证断言)
  • npx tsc --noEmit 通过;前端 147/147 通过
  • applyAuthSession 消费面核实:access_token 仅作 truthy presence(setAuthToken('1')),占位值无行为差异

Verifier verdict

CI 门禁即机器 Verifier;「fragment 无凭证」由 GitHub/Google 双 mock 回归独立钉死。真实 provider 端到端(含登出)留待有真实 OAuth 应用环境时人工回归——已在 #63 关闭评论中说明。

Checklist

  • Branch named issue-<number>-<short-slug> and PR links the issue
  • 无本地文件入库

@fxbin
fxbin merged commit 83a1843 into main Sep 27, 2026
5 checks passed
@fxbin
fxbin deleted the issue-63-tokenless-fragment branch September 28, 2026 15:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[P2][Security] OAuth 回调经 URL Fragment 向前端传递完整登录凭证

1 participant