fix(vloer): bind OIDC sign-in and account links to the starting browser #143

Merged
ryangr0 merged 1 commit from ryangr0/vloer-oauth-browser-binding into development 2026-10-03 00:02:14 +00:00 AGit
Owner

Pending OIDC sign-ins and GitLab/ClickUp link flows were kept in
process-wide maps keyed only by state, so a different browser could finish
them: login CSRF for sign-in, and a victim's provider token attached to an
attacker's account for links. Starting a flow now sets a random HttpOnly
SameSite=Lax cookie whose digest is stored with the pending flow, and a
callback without the matching cookie is refused before the code exchange.
The session cookie stays SameSite=Strict. Prepared in the 2026-10-02
Execution Pack.

Does not cover the editor sign-in approval step (VIK-1718).

Verified with mise run verify on the pinned toolchain (all gates passed).

Ticket: https://vikunja.webgrip.dev/tasks/1717

🤖 Generated with Claude Code

Pending OIDC sign-ins and GitLab/ClickUp link flows were kept in process-wide maps keyed only by state, so a different browser could finish them: login CSRF for sign-in, and a victim's provider token attached to an attacker's account for links. Starting a flow now sets a random HttpOnly SameSite=Lax cookie whose digest is stored with the pending flow, and a callback without the matching cookie is refused before the code exchange. The session cookie stays SameSite=Strict. Prepared in the 2026-10-02 Execution Pack. Does not cover the editor sign-in approval step (VIK-1718). Verified with `mise run verify` on the pinned toolchain (all gates passed). Ticket: https://vikunja.webgrip.dev/tasks/1717 🤖 Generated with [Claude Code](https://claude.com/claude-code)
fix(vloer): bind OIDC sign-in and account links to the starting browser
Some checks failed
[Workflow] On Pull Request / checks (pull_request) Has been cancelled
[Workflow] On Pull Request / warnings (pull_request) Has been cancelled
[Workflow] On Pull Request / release-policy (pull_request) Has been cancelled
999883628f
Pending OIDC sign-ins and GitLab/ClickUp link flows were kept in
process-wide maps keyed only by state, so a different browser could finish
them: login CSRF for sign-in, and a victim's provider token attached to an
attacker's account for links. Starting a flow now sets a random HttpOnly
SameSite=Lax cookie whose digest is stored with the pending flow, and a
callback without the matching cookie is refused before the code exchange.
The session cookie stays SameSite=Strict. Prepared in the 2026-10-02
Execution Pack.

VIK-1717

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
ryangr0 merged commit dc53a075b7 into development 2026-10-03 00:02:14 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
webgrip/unfold!143
No description provided.