fix(vloer): bind OIDC sign-in and account links to the starting browser #143
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "ryangr0/vloer-oauth-browser-binding"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Pending OIDC sign-ins and GitLab/ClickUp link flows were kept in
process-wide maps keyed only by state, so a different browser could finish
them: login CSRF for sign-in, and a victim's provider token attached to an
attacker's account for links. Starting a flow now sets a random HttpOnly
SameSite=Lax cookie whose digest is stored with the pending flow, and a
callback without the matching cookie is refused before the code exchange.
The session cookie stays SameSite=Strict. Prepared in the 2026-10-02
Execution Pack.
Does not cover the editor sign-in approval step (VIK-1718).
Verified with
mise run verifyon the pinned toolchain (all gates passed).Ticket: https://vikunja.webgrip.dev/tasks/1717
🤖 Generated with Claude Code