fix(web): reject OAuth account-linking without a signed-in session - #1221

Merged
msukkari merged 7 commits into
mainfrom
msukkari/fix-oauth-linking-orphan
May 22, 2026
Merged

fix(web): reject OAuth account-linking without a signed-in session#1221
msukkari merged 7 commits into
mainfrom
msukkari/fix-oauth-linking-orphan

Conversation

@msukkari

@msukkarimsukkari commented May 22, 2026

Copy link
Copy Markdown
Contributor

Summary

OAuth providers configured with `purpose: "account_linking"` should only ever attach an identity to an existing signed-in user, never mint a new Sourcebot user. `@auth/core` does not know about this distinction and falls back to `createUser` when its session lookup returns null, which can happen when the user's session cookie expires while they are on the upstream consent screen. The result is a silent orphan `User` row and a confused user.

Add a `signIn` callback that refuses the request in that case.

Test plan

  • TypeScript build clean (`yarn workspace @sourcebot/web build`).
  • Docker image builds and boots cleanly.
  • Live negative path: sign in as Bob, click Disconnect, click Connect, wait past `AUTH_SESSION_MAX_AGE_SECONDS` on the BB consent screen, approve. Expect Sourcebot to land on the error page with no orphan User or Account row created.
  • Live positive path: sign in as Bob, click Connect, approve on BB within the session lifetime. Expect Pan Owner to link cleanly to Bob.
  • Live regression check: credentials login still works (no OAuth account on the request, signIn returns true early).

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Bug Fixes

    • OAuth account-linking now rejects sign-in attempts without an active authenticated session, preventing orphaned user accounts.
    • Credential sign-in now fails safely when an existing account lacks a stored password, avoiding invalid password checks.
  • Documentation

    • Changelog updated under Unreleased → Fixed to record these account-linking and credential behavior changes.

Review Change Stack

If a user clicks "Connect Bitbucket" and their session-token cookie is
missing or expired by the time the BB redirect arrives at our callback,
@auth/core silently falls through to createUser and mints a new orphan
User row from the OAuth profile. The orphan has no email, no UserToOrg,
and the user's session cookie gets rebound to it, leaving them on a
"request access" page.
Add a signIn callback that calls auth() and refuses the request when
the provider's purpose is account_linking and no session is present.
SSO providers and credentials login are unaffected.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitaiBot commented May 22, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

Pull request was closed or merged during review

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

Walkthrough

Adds a NextAuth callbacks.signIn handler that resolves the configured provider, treats OAuth/OIDC sign-ins with purpose: "account_linking" as account-linking attempts, calls auth() to get the current session, and rejects account-linking sign-ins when no authenticated session exists. A CHANGELOG entry documents the fix.

Changes

OAuth Account-Linking Session Validation

Layer / File(s)Summary
Credentials authorize safeguard
packages/web/src/auth.ts
In the credentials provider authorize flow, return null when an existing user has no hashedPassword, aborting credential authentication.
Sign-in callback and provider ID resolution
packages/web/src/auth.ts, CHANGELOG.md
Adds callbacks.signIn that matches account.provider to configured providers (using getEffectiveProviderId to read provider.id or provider.options.id), calls auth(), and denies sign-in for purpose: "account_linking" when auth() returns null. Updates CHANGELOG.md with a Fixed note about rejecting account-linking without a signed-in session.

Sequence Diagram

sequenceDiagram
participant Client
participant NextAuth
participant ProviderRegistry
participant AuthResolver
Client->>NextAuth: OAuth/OIDC provider callback (account)
NextAuth->>ProviderRegistry: getProviders() -> find provider for account.provider
NextAuth->>AuthResolver: auth() to resolve current session (if provider.purpose == "account_linking")
AuthResolver-->>NextAuth: session or null
NextAuth-->>Client: allow or deny sign-in (deny if account_linking && session == null)
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

Suggested reviewers

  • brendan-kellam
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately and concisely describes the main change: preventing OAuth account-linking when no signed-in session exists, which is the core objective of the PR.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch msukkari/fix-oauth-linking-orphan

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

msukkariand others added 5 commits May 21, 2026 20:59
The fix is gated behind the sso entitlement (no OAuth identity
providers are loaded in OSS deployments), so the [EE] prefix is
appropriate per CLAUDE.md.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
packages/web/src/auth.ts (1)

283-290: ⚡ Quick win

Only resolve the session for account-linking flows.

auth() runs on every sign-in attempt, but only the account_linking branch uses its result. Moving the lookup inside that branch keeps credentials/email/SSO logins off the extra session decode/DB path.

♻️ Proposed change
- const isAccountLinkingAttempt = matchingProvider?.purpose === 'account_linking';- const session = await auth();-- if (isAccountLinkingAttempt && session === null) {- return false;- }-- return true;+ if (matchingProvider?.purpose !== 'account_linking') {+ return true;+ }++ const session = await auth();+ return session !== null;
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/web/src/auth.ts` around lines 283 - 290, The code currently calls
auth() unconditionally; change it so we only call auth() when
matchingProvider?.purpose === 'account_linking' by moving the session lookup
inside that branch: compute isAccountLinkingAttempt from matchingProvider, and
if true then await auth() and return false if the session is null, otherwise
proceed to return true; remove the unconditional auth() call so
non-account_linking sign-ins avoid the extra session decode/DB path.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/web/src/auth.ts`:
- Around line 243-260: Extract a shared helper (e.g.,
getEffectiveProviderId(provider)) that returns config.options?.id ?? config.id
and replace the inline resolver in callbacks.signIn() (where matchingProvider is
computed) and in getIssuerUrlForAccount() so both paths use the same effective
provider id logic; additionally, defer calling auth() to fetch the session by
moving "const session = await auth()" behind a guard so it only runs when
matchingProvider?.purpose === 'account_linking' (instead of running
unconditionally during every sign-in).
---
Nitpick comments:
In `@packages/web/src/auth.ts`:
- Around line 283-290: The code currently calls auth() unconditionally; change
it so we only call auth() when matchingProvider?.purpose === 'account_linking'
by moving the session lookup inside that branch: compute isAccountLinkingAttempt
from matchingProvider, and if true then await auth() and return false if the
session is null, otherwise proceed to return true; remove the unconditional
auth() call so non-account_linking sign-ins avoid the extra session decode/DB
path.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 420486e4-3fea-443c-bc74-a8f7c099f806

📥 Commits

Reviewing files that changed from the base of the PR and between 18c3dab and 85af3fe.

📒 Files selected for processing (1)
  • packages/web/src/auth.ts

Comment threadpackages/web/src/auth.ts Outdated
Shared between signIn callback and getIssuerUrlForAccount. The latter previously read only the top-level provider id, which silently returned undefined for factory-based providers with an `id:` override (Bitbucket Cloud, GitHub, GitLab, Google, Okta, Keycloak, Entra, Authentik), meaning the stored issuerUrl was never resolved correctly for those accounts.
@msukkari
msukkari merged commit 987e6e4 into mainMay 22, 2026
8 of 9 checks passed
@github-actionsgithub-actionsBot mentioned this pull request May 22, 2026
@msukkari
msukkari deleted the msukkari/fix-oauth-linking-orphan branch May 22, 2026 20:55
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@msukkari
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all \u003cpre\u003e\u003ccode\u003e blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks"); } } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); } })(); (function(){ try { var __m = "github.com"; var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix(web): reject OAuth account-linking without a signed-in session - #1221

Merged
msukkari merged 7 commits into
mainfrom
msukkari/fix-oauth-linking-orphan
May 22, 2026
Merged

fix(web): reject OAuth account-linking without a signed-in session#1221
msukkari merged 7 commits into
mainfrom
msukkari/fix-oauth-linking-orphan

Conversation

@msukkari

@msukkarimsukkari commented May 22, 2026

Copy link
Copy Markdown
Contributor

Summary

OAuth providers configured with `purpose: "account_linking"` should only ever attach an identity to an existing signed-in user, never mint a new Sourcebot user. `@auth/core` does not know about this distinction and falls back to `createUser` when its session lookup returns null, which can happen when the user's session cookie expires while they are on the upstream consent screen. The result is a silent orphan `User` row and a confused user.

Add a `signIn` callback that refuses the request in that case.

Test plan

  • TypeScript build clean (`yarn workspace @sourcebot/web build`).
  • Docker image builds and boots cleanly.
  • Live negative path: sign in as Bob, click Disconnect, click Connect, wait past `AUTH_SESSION_MAX_AGE_SECONDS` on the BB consent screen, approve. Expect Sourcebot to land on the error page with no orphan User or Account row created.
  • Live positive path: sign in as Bob, click Connect, approve on BB within the session lifetime. Expect Pan Owner to link cleanly to Bob.
  • Live regression check: credentials login still works (no OAuth account on the request, signIn returns true early).

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Bug Fixes

    • OAuth account-linking now rejects sign-in attempts without an active authenticated session, preventing orphaned user accounts.
    • Credential sign-in now fails safely when an existing account lacks a stored password, avoiding invalid password checks.
  • Documentation

    • Changelog updated under Unreleased → Fixed to record these account-linking and credential behavior changes.

Review Change Stack

If a user clicks "Connect Bitbucket" and their session-token cookie is
missing or expired by the time the BB redirect arrives at our callback,
@auth/core silently falls through to createUser and mints a new orphan
User row from the OAuth profile. The orphan has no email, no UserToOrg,
and the user's session cookie gets rebound to it, leaving them on a
"request access" page.
Add a signIn callback that calls auth() and refuses the request when
the provider's purpose is account_linking and no session is present.
SSO providers and credentials login are unaffected.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitaiBot commented May 22, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

Pull request was closed or merged during review

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

Walkthrough

Adds a NextAuth callbacks.signIn handler that resolves the configured provider, treats OAuth/OIDC sign-ins with purpose: "account_linking" as account-linking attempts, calls auth() to get the current session, and rejects account-linking sign-ins when no authenticated session exists. A CHANGELOG entry documents the fix.

Changes

OAuth Account-Linking Session Validation

Layer / File(s)Summary
Credentials authorize safeguard
packages/web/src/auth.ts
In the credentials provider authorize flow, return null when an existing user has no hashedPassword, aborting credential authentication.
Sign-in callback and provider ID resolution
packages/web/src/auth.ts, CHANGELOG.md
Adds callbacks.signIn that matches account.provider to configured providers (using getEffectiveProviderId to read provider.id or provider.options.id), calls auth(), and denies sign-in for purpose: "account_linking" when auth() returns null. Updates CHANGELOG.md with a Fixed note about rejecting account-linking without a signed-in session.

Sequence Diagram

sequenceDiagram
participant Client
participant NextAuth
participant ProviderRegistry
participant AuthResolver
Client->>NextAuth: OAuth/OIDC provider callback (account)
NextAuth->>ProviderRegistry: getProviders() -> find provider for account.provider
NextAuth->>AuthResolver: auth() to resolve current session (if provider.purpose == "account_linking")
AuthResolver-->>NextAuth: session or null
NextAuth-->>Client: allow or deny sign-in (deny if account_linking && session == null)
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

Suggested reviewers

  • brendan-kellam
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately and concisely describes the main change: preventing OAuth account-linking when no signed-in session exists, which is the core objective of the PR.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch msukkari/fix-oauth-linking-orphan

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

msukkariand others added 5 commits May 21, 2026 20:59
The fix is gated behind the sso entitlement (no OAuth identity
providers are loaded in OSS deployments), so the [EE] prefix is
appropriate per CLAUDE.md.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
packages/web/src/auth.ts (1)

283-290: ⚡ Quick win

Only resolve the session for account-linking flows.

auth() runs on every sign-in attempt, but only the account_linking branch uses its result. Moving the lookup inside that branch keeps credentials/email/SSO logins off the extra session decode/DB path.

♻️ Proposed change
- const isAccountLinkingAttempt = matchingProvider?.purpose === 'account_linking';- const session = await auth();-- if (isAccountLinkingAttempt && session === null) {- return false;- }-- return true;+ if (matchingProvider?.purpose !== 'account_linking') {+ return true;+ }++ const session = await auth();+ return session !== null;
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/web/src/auth.ts` around lines 283 - 290, The code currently calls
auth() unconditionally; change it so we only call auth() when
matchingProvider?.purpose === 'account_linking' by moving the session lookup
inside that branch: compute isAccountLinkingAttempt from matchingProvider, and
if true then await auth() and return false if the session is null, otherwise
proceed to return true; remove the unconditional auth() call so
non-account_linking sign-ins avoid the extra session decode/DB path.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/web/src/auth.ts`:
- Around line 243-260: Extract a shared helper (e.g.,
getEffectiveProviderId(provider)) that returns config.options?.id ?? config.id
and replace the inline resolver in callbacks.signIn() (where matchingProvider is
computed) and in getIssuerUrlForAccount() so both paths use the same effective
provider id logic; additionally, defer calling auth() to fetch the session by
moving "const session = await auth()" behind a guard so it only runs when
matchingProvider?.purpose === 'account_linking' (instead of running
unconditionally during every sign-in).
---
Nitpick comments:
In `@packages/web/src/auth.ts`:
- Around line 283-290: The code currently calls auth() unconditionally; change
it so we only call auth() when matchingProvider?.purpose === 'account_linking'
by moving the session lookup inside that branch: compute isAccountLinkingAttempt
from matchingProvider, and if true then await auth() and return false if the
session is null, otherwise proceed to return true; remove the unconditional
auth() call so non-account_linking sign-ins avoid the extra session decode/DB
path.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 420486e4-3fea-443c-bc74-a8f7c099f806

📥 Commits

Reviewing files that changed from the base of the PR and between 18c3dab and 85af3fe.

📒 Files selected for processing (1)
  • packages/web/src/auth.ts

Comment threadpackages/web/src/auth.ts Outdated
Shared between signIn callback and getIssuerUrlForAccount. The latter previously read only the top-level provider id, which silently returned undefined for factory-based providers with an `id:` override (Bitbucket Cloud, GitHub, GitLab, Google, Okta, Keycloak, Entra, Authentik), meaning the stored issuerUrl was never resolved correctly for those accounts.
@msukkari
msukkari merged commit 987e6e4 into mainMay 22, 2026
8 of 9 checks passed
@github-actionsgithub-actionsBot mentioned this pull request May 22, 2026
@msukkari
msukkari deleted the msukkari/fix-oauth-linking-orphan branch May 22, 2026 20:55
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@msukkari
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(web): reject OAuth account-linking without a signed-in session - #1221

Merged
msukkari merged 7 commits into
mainfrom
msukkari/fix-oauth-linking-orphan
May 22, 2026
Merged

fix(web): reject OAuth account-linking without a signed-in session#1221
msukkari merged 7 commits into
mainfrom
msukkari/fix-oauth-linking-orphan

Conversation

@msukkari

@msukkarimsukkari commented May 22, 2026

Copy link
Copy Markdown
Contributor

Summary

OAuth providers configured with `purpose: "account_linking"` should only ever attach an identity to an existing signed-in user, never mint a new Sourcebot user. `@auth/core` does not know about this distinction and falls back to `createUser` when its session lookup returns null, which can happen when the user's session cookie expires while they are on the upstream consent screen. The result is a silent orphan `User` row and a confused user.

Add a `signIn` callback that refuses the request in that case.

Test plan

  • TypeScript build clean (`yarn workspace @sourcebot/web build`).
  • Docker image builds and boots cleanly.
  • Live negative path: sign in as Bob, click Disconnect, click Connect, wait past `AUTH_SESSION_MAX_AGE_SECONDS` on the BB consent screen, approve. Expect Sourcebot to land on the error page with no orphan User or Account row created.
  • Live positive path: sign in as Bob, click Connect, approve on BB within the session lifetime. Expect Pan Owner to link cleanly to Bob.
  • Live regression check: credentials login still works (no OAuth account on the request, signIn returns true early).

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Bug Fixes

    • OAuth account-linking now rejects sign-in attempts without an active authenticated session, preventing orphaned user accounts.
    • Credential sign-in now fails safely when an existing account lacks a stored password, avoiding invalid password checks.
  • Documentation

    • Changelog updated under Unreleased → Fixed to record these account-linking and credential behavior changes.

Review Change Stack

If a user clicks "Connect Bitbucket" and their session-token cookie is
missing or expired by the time the BB redirect arrives at our callback,
@auth/core silently falls through to createUser and mints a new orphan
User row from the OAuth profile. The orphan has no email, no UserToOrg,
and the user's session cookie gets rebound to it, leaving them on a
"request access" page.
Add a signIn callback that calls auth() and refuses the request when
the provider's purpose is account_linking and no session is present.
SSO providers and credentials login are unaffected.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitaiBot commented May 22, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

Pull request was closed or merged during review

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

Walkthrough

Adds a NextAuth callbacks.signIn handler that resolves the configured provider, treats OAuth/OIDC sign-ins with purpose: "account_linking" as account-linking attempts, calls auth() to get the current session, and rejects account-linking sign-ins when no authenticated session exists. A CHANGELOG entry documents the fix.

Changes

OAuth Account-Linking Session Validation

Layer / File(s)Summary
Credentials authorize safeguard
packages/web/src/auth.ts
In the credentials provider authorize flow, return null when an existing user has no hashedPassword, aborting credential authentication.
Sign-in callback and provider ID resolution
packages/web/src/auth.ts, CHANGELOG.md
Adds callbacks.signIn that matches account.provider to configured providers (using getEffectiveProviderId to read provider.id or provider.options.id), calls auth(), and denies sign-in for purpose: "account_linking" when auth() returns null. Updates CHANGELOG.md with a Fixed note about rejecting account-linking without a signed-in session.

Sequence Diagram

sequenceDiagram
participant Client
participant NextAuth
participant ProviderRegistry
participant AuthResolver
Client->>NextAuth: OAuth/OIDC provider callback (account)
NextAuth->>ProviderRegistry: getProviders() -> find provider for account.provider
NextAuth->>AuthResolver: auth() to resolve current session (if provider.purpose == "account_linking")
AuthResolver-->>NextAuth: session or null
NextAuth-->>Client: allow or deny sign-in (deny if account_linking && session == null)
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

Suggested reviewers

  • brendan-kellam
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately and concisely describes the main change: preventing OAuth account-linking when no signed-in session exists, which is the core objective of the PR.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch msukkari/fix-oauth-linking-orphan

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

msukkariand others added 5 commits May 21, 2026 20:59
The fix is gated behind the sso entitlement (no OAuth identity
providers are loaded in OSS deployments), so the [EE] prefix is
appropriate per CLAUDE.md.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
packages/web/src/auth.ts (1)

283-290: ⚡ Quick win

Only resolve the session for account-linking flows.

auth() runs on every sign-in attempt, but only the account_linking branch uses its result. Moving the lookup inside that branch keeps credentials/email/SSO logins off the extra session decode/DB path.

♻️ Proposed change
- const isAccountLinkingAttempt = matchingProvider?.purpose === 'account_linking';- const session = await auth();-- if (isAccountLinkingAttempt && session === null) {- return false;- }-- return true;+ if (matchingProvider?.purpose !== 'account_linking') {+ return true;+ }++ const session = await auth();+ return session !== null;
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/web/src/auth.ts` around lines 283 - 290, The code currently calls
auth() unconditionally; change it so we only call auth() when
matchingProvider?.purpose === 'account_linking' by moving the session lookup
inside that branch: compute isAccountLinkingAttempt from matchingProvider, and
if true then await auth() and return false if the session is null, otherwise
proceed to return true; remove the unconditional auth() call so
non-account_linking sign-ins avoid the extra session decode/DB path.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/web/src/auth.ts`:
- Around line 243-260: Extract a shared helper (e.g.,
getEffectiveProviderId(provider)) that returns config.options?.id ?? config.id
and replace the inline resolver in callbacks.signIn() (where matchingProvider is
computed) and in getIssuerUrlForAccount() so both paths use the same effective
provider id logic; additionally, defer calling auth() to fetch the session by
moving "const session = await auth()" behind a guard so it only runs when
matchingProvider?.purpose === 'account_linking' (instead of running
unconditionally during every sign-in).
---
Nitpick comments:
In `@packages/web/src/auth.ts`:
- Around line 283-290: The code currently calls auth() unconditionally; change
it so we only call auth() when matchingProvider?.purpose === 'account_linking'
by moving the session lookup inside that branch: compute isAccountLinkingAttempt
from matchingProvider, and if true then await auth() and return false if the
session is null, otherwise proceed to return true; remove the unconditional
auth() call so non-account_linking sign-ins avoid the extra session decode/DB
path.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 420486e4-3fea-443c-bc74-a8f7c099f806

📥 Commits

Reviewing files that changed from the base of the PR and between 18c3dab and 85af3fe.

📒 Files selected for processing (1)
  • packages/web/src/auth.ts

Comment threadpackages/web/src/auth.ts Outdated
Shared between signIn callback and getIssuerUrlForAccount. The latter previously read only the top-level provider id, which silently returned undefined for factory-based providers with an `id:` override (Bitbucket Cloud, GitHub, GitLab, Google, Okta, Keycloak, Entra, Authentik), meaning the stored issuerUrl was never resolved correctly for those accounts.
@msukkari
msukkari merged commit 987e6e4 into mainMay 22, 2026
8 of 9 checks passed
@github-actionsgithub-actionsBot mentioned this pull request May 22, 2026
@msukkari
msukkari deleted the msukkari/fix-oauth-linking-orphan branch May 22, 2026 20:55
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@msukkari
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length \u003e 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(web): reject OAuth account-linking without a signed-in session - #1221

Merged
msukkari merged 7 commits into
mainfrom
msukkari/fix-oauth-linking-orphan
May 22, 2026
Merged

fix(web): reject OAuth account-linking without a signed-in session#1221
msukkari merged 7 commits into
mainfrom
msukkari/fix-oauth-linking-orphan

Conversation

@msukkari

@msukkarimsukkari commented May 22, 2026

Copy link
Copy Markdown
Contributor

Summary

OAuth providers configured with `purpose: "account_linking"` should only ever attach an identity to an existing signed-in user, never mint a new Sourcebot user. `@auth/core` does not know about this distinction and falls back to `createUser` when its session lookup returns null, which can happen when the user's session cookie expires while they are on the upstream consent screen. The result is a silent orphan `User` row and a confused user.

Add a `signIn` callback that refuses the request in that case.

Test plan

  • TypeScript build clean (`yarn workspace @sourcebot/web build`).
  • Docker image builds and boots cleanly.
  • Live negative path: sign in as Bob, click Disconnect, click Connect, wait past `AUTH_SESSION_MAX_AGE_SECONDS` on the BB consent screen, approve. Expect Sourcebot to land on the error page with no orphan User or Account row created.
  • Live positive path: sign in as Bob, click Connect, approve on BB within the session lifetime. Expect Pan Owner to link cleanly to Bob.
  • Live regression check: credentials login still works (no OAuth account on the request, signIn returns true early).

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Bug Fixes

    • OAuth account-linking now rejects sign-in attempts without an active authenticated session, preventing orphaned user accounts.
    • Credential sign-in now fails safely when an existing account lacks a stored password, avoiding invalid password checks.
  • Documentation

    • Changelog updated under Unreleased → Fixed to record these account-linking and credential behavior changes.

Review Change Stack

If a user clicks "Connect Bitbucket" and their session-token cookie is
missing or expired by the time the BB redirect arrives at our callback,
@auth/core silently falls through to createUser and mints a new orphan
User row from the OAuth profile. The orphan has no email, no UserToOrg,
and the user's session cookie gets rebound to it, leaving them on a
"request access" page.
Add a signIn callback that calls auth() and refuses the request when
the provider's purpose is account_linking and no session is present.
SSO providers and credentials login are unaffected.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitaiBot commented May 22, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

Pull request was closed or merged during review

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

Walkthrough

Adds a NextAuth callbacks.signIn handler that resolves the configured provider, treats OAuth/OIDC sign-ins with purpose: "account_linking" as account-linking attempts, calls auth() to get the current session, and rejects account-linking sign-ins when no authenticated session exists. A CHANGELOG entry documents the fix.

Changes

OAuth Account-Linking Session Validation

Layer / File(s)Summary
Credentials authorize safeguard
packages/web/src/auth.ts
In the credentials provider authorize flow, return null when an existing user has no hashedPassword, aborting credential authentication.
Sign-in callback and provider ID resolution
packages/web/src/auth.ts, CHANGELOG.md
Adds callbacks.signIn that matches account.provider to configured providers (using getEffectiveProviderId to read provider.id or provider.options.id), calls auth(), and denies sign-in for purpose: "account_linking" when auth() returns null. Updates CHANGELOG.md with a Fixed note about rejecting account-linking without a signed-in session.

Sequence Diagram

sequenceDiagram
participant Client
participant NextAuth
participant ProviderRegistry
participant AuthResolver
Client->>NextAuth: OAuth/OIDC provider callback (account)
NextAuth->>ProviderRegistry: getProviders() -> find provider for account.provider
NextAuth->>AuthResolver: auth() to resolve current session (if provider.purpose == "account_linking")
AuthResolver-->>NextAuth: session or null
NextAuth-->>Client: allow or deny sign-in (deny if account_linking && session == null)
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

Suggested reviewers

  • brendan-kellam
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately and concisely describes the main change: preventing OAuth account-linking when no signed-in session exists, which is the core objective of the PR.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch msukkari/fix-oauth-linking-orphan

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

msukkariand others added 5 commits May 21, 2026 20:59
The fix is gated behind the sso entitlement (no OAuth identity
providers are loaded in OSS deployments), so the [EE] prefix is
appropriate per CLAUDE.md.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
packages/web/src/auth.ts (1)

283-290: ⚡ Quick win

Only resolve the session for account-linking flows.

auth() runs on every sign-in attempt, but only the account_linking branch uses its result. Moving the lookup inside that branch keeps credentials/email/SSO logins off the extra session decode/DB path.

♻️ Proposed change
- const isAccountLinkingAttempt = matchingProvider?.purpose === 'account_linking';- const session = await auth();-- if (isAccountLinkingAttempt && session === null) {- return false;- }-- return true;+ if (matchingProvider?.purpose !== 'account_linking') {+ return true;+ }++ const session = await auth();+ return session !== null;
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/web/src/auth.ts` around lines 283 - 290, The code currently calls
auth() unconditionally; change it so we only call auth() when
matchingProvider?.purpose === 'account_linking' by moving the session lookup
inside that branch: compute isAccountLinkingAttempt from matchingProvider, and
if true then await auth() and return false if the session is null, otherwise
proceed to return true; remove the unconditional auth() call so
non-account_linking sign-ins avoid the extra session decode/DB path.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/web/src/auth.ts`:
- Around line 243-260: Extract a shared helper (e.g.,
getEffectiveProviderId(provider)) that returns config.options?.id ?? config.id
and replace the inline resolver in callbacks.signIn() (where matchingProvider is
computed) and in getIssuerUrlForAccount() so both paths use the same effective
provider id logic; additionally, defer calling auth() to fetch the session by
moving "const session = await auth()" behind a guard so it only runs when
matchingProvider?.purpose === 'account_linking' (instead of running
unconditionally during every sign-in).
---
Nitpick comments:
In `@packages/web/src/auth.ts`:
- Around line 283-290: The code currently calls auth() unconditionally; change
it so we only call auth() when matchingProvider?.purpose === 'account_linking'
by moving the session lookup inside that branch: compute isAccountLinkingAttempt
from matchingProvider, and if true then await auth() and return false if the
session is null, otherwise proceed to return true; remove the unconditional
auth() call so non-account_linking sign-ins avoid the extra session decode/DB
path.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 420486e4-3fea-443c-bc74-a8f7c099f806

📥 Commits

Reviewing files that changed from the base of the PR and between 18c3dab and 85af3fe.

📒 Files selected for processing (1)
  • packages/web/src/auth.ts

Comment threadpackages/web/src/auth.ts Outdated
Shared between signIn callback and getIssuerUrlForAccount. The latter previously read only the top-level provider id, which silently returned undefined for factory-based providers with an `id:` override (Bitbucket Cloud, GitHub, GitLab, Google, Okta, Keycloak, Entra, Authentik), meaning the stored issuerUrl was never resolved correctly for those accounts.
@msukkari
msukkari merged commit 987e6e4 into mainMay 22, 2026
8 of 9 checks passed
@github-actionsgithub-actionsBot mentioned this pull request May 22, 2026
@msukkari
msukkari deleted the msukkari/fix-oauth-linking-orphan branch May 22, 2026 20:55
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@msukkari
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix(web): reject OAuth account-linking without a signed-in session - #1221

Merged
msukkari merged 7 commits into
mainfrom
msukkari/fix-oauth-linking-orphan
May 22, 2026
Merged

fix(web): reject OAuth account-linking without a signed-in session#1221
msukkari merged 7 commits into
mainfrom
msukkari/fix-oauth-linking-orphan

Conversation

@msukkari

@msukkarimsukkari commented May 22, 2026

Copy link
Copy Markdown
Contributor

Summary

OAuth providers configured with `purpose: "account_linking"` should only ever attach an identity to an existing signed-in user, never mint a new Sourcebot user. `@auth/core` does not know about this distinction and falls back to `createUser` when its session lookup returns null, which can happen when the user's session cookie expires while they are on the upstream consent screen. The result is a silent orphan `User` row and a confused user.

Add a `signIn` callback that refuses the request in that case.

Test plan

  • TypeScript build clean (`yarn workspace @sourcebot/web build`).
  • Docker image builds and boots cleanly.
  • Live negative path: sign in as Bob, click Disconnect, click Connect, wait past `AUTH_SESSION_MAX_AGE_SECONDS` on the BB consent screen, approve. Expect Sourcebot to land on the error page with no orphan User or Account row created.
  • Live positive path: sign in as Bob, click Connect, approve on BB within the session lifetime. Expect Pan Owner to link cleanly to Bob.
  • Live regression check: credentials login still works (no OAuth account on the request, signIn returns true early).

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Bug Fixes

    • OAuth account-linking now rejects sign-in attempts without an active authenticated session, preventing orphaned user accounts.
    • Credential sign-in now fails safely when an existing account lacks a stored password, avoiding invalid password checks.
  • Documentation

    • Changelog updated under Unreleased → Fixed to record these account-linking and credential behavior changes.

Review Change Stack

If a user clicks "Connect Bitbucket" and their session-token cookie is
missing or expired by the time the BB redirect arrives at our callback,
@auth/core silently falls through to createUser and mints a new orphan
User row from the OAuth profile. The orphan has no email, no UserToOrg,
and the user's session cookie gets rebound to it, leaving them on a
"request access" page.
Add a signIn callback that calls auth() and refuses the request when
the provider's purpose is account_linking and no session is present.
SSO providers and credentials login are unaffected.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitaiBot commented May 22, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

Pull request was closed or merged during review

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

Walkthrough

Adds a NextAuth callbacks.signIn handler that resolves the configured provider, treats OAuth/OIDC sign-ins with purpose: "account_linking" as account-linking attempts, calls auth() to get the current session, and rejects account-linking sign-ins when no authenticated session exists. A CHANGELOG entry documents the fix.

Changes

OAuth Account-Linking Session Validation

Layer / File(s)Summary
Credentials authorize safeguard
packages/web/src/auth.ts
In the credentials provider authorize flow, return null when an existing user has no hashedPassword, aborting credential authentication.
Sign-in callback and provider ID resolution
packages/web/src/auth.ts, CHANGELOG.md
Adds callbacks.signIn that matches account.provider to configured providers (using getEffectiveProviderId to read provider.id or provider.options.id), calls auth(), and denies sign-in for purpose: "account_linking" when auth() returns null. Updates CHANGELOG.md with a Fixed note about rejecting account-linking without a signed-in session.

Sequence Diagram

sequenceDiagram
participant Client
participant NextAuth
participant ProviderRegistry
participant AuthResolver
Client->>NextAuth: OAuth/OIDC provider callback (account)
NextAuth->>ProviderRegistry: getProviders() -> find provider for account.provider
NextAuth->>AuthResolver: auth() to resolve current session (if provider.purpose == "account_linking")
AuthResolver-->>NextAuth: session or null
NextAuth-->>Client: allow or deny sign-in (deny if account_linking && session == null)
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

Suggested reviewers

  • brendan-kellam
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately and concisely describes the main change: preventing OAuth account-linking when no signed-in session exists, which is the core objective of the PR.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch msukkari/fix-oauth-linking-orphan

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

msukkariand others added 5 commits May 21, 2026 20:59
The fix is gated behind the sso entitlement (no OAuth identity
providers are loaded in OSS deployments), so the [EE] prefix is
appropriate per CLAUDE.md.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
packages/web/src/auth.ts (1)

283-290: ⚡ Quick win

Only resolve the session for account-linking flows.

auth() runs on every sign-in attempt, but only the account_linking branch uses its result. Moving the lookup inside that branch keeps credentials/email/SSO logins off the extra session decode/DB path.

♻️ Proposed change
- const isAccountLinkingAttempt = matchingProvider?.purpose === 'account_linking';- const session = await auth();-- if (isAccountLinkingAttempt && session === null) {- return false;- }-- return true;+ if (matchingProvider?.purpose !== 'account_linking') {+ return true;+ }++ const session = await auth();+ return session !== null;
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/web/src/auth.ts` around lines 283 - 290, The code currently calls
auth() unconditionally; change it so we only call auth() when
matchingProvider?.purpose === 'account_linking' by moving the session lookup
inside that branch: compute isAccountLinkingAttempt from matchingProvider, and
if true then await auth() and return false if the session is null, otherwise
proceed to return true; remove the unconditional auth() call so
non-account_linking sign-ins avoid the extra session decode/DB path.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/web/src/auth.ts`:
- Around line 243-260: Extract a shared helper (e.g.,
getEffectiveProviderId(provider)) that returns config.options?.id ?? config.id
and replace the inline resolver in callbacks.signIn() (where matchingProvider is
computed) and in getIssuerUrlForAccount() so both paths use the same effective
provider id logic; additionally, defer calling auth() to fetch the session by
moving "const session = await auth()" behind a guard so it only runs when
matchingProvider?.purpose === 'account_linking' (instead of running
unconditionally during every sign-in).
---
Nitpick comments:
In `@packages/web/src/auth.ts`:
- Around line 283-290: The code currently calls auth() unconditionally; change
it so we only call auth() when matchingProvider?.purpose === 'account_linking'
by moving the session lookup inside that branch: compute isAccountLinkingAttempt
from matchingProvider, and if true then await auth() and return false if the
session is null, otherwise proceed to return true; remove the unconditional
auth() call so non-account_linking sign-ins avoid the extra session decode/DB
path.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 420486e4-3fea-443c-bc74-a8f7c099f806

📥 Commits

Reviewing files that changed from the base of the PR and between 18c3dab and 85af3fe.

📒 Files selected for processing (1)
  • packages/web/src/auth.ts

Comment threadpackages/web/src/auth.ts Outdated
Shared between signIn callback and getIssuerUrlForAccount. The latter previously read only the top-level provider id, which silently returned undefined for factory-based providers with an `id:` override (Bitbucket Cloud, GitHub, GitLab, Google, Okta, Keycloak, Entra, Authentik), meaning the stored issuerUrl was never resolved correctly for those accounts.
@msukkari
msukkari merged commit 987e6e4 into mainMay 22, 2026
8 of 9 checks passed
@github-actionsgithub-actionsBot mentioned this pull request May 22, 2026
@msukkari
msukkari deleted the msukkari/fix-oauth-linking-orphan branch May 22, 2026 20:55
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@msukkari
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(web): reject OAuth account-linking without a signed-in session - #1221

Merged
msukkari merged 7 commits into
mainfrom
msukkari/fix-oauth-linking-orphan
May 22, 2026
Merged

fix(web): reject OAuth account-linking without a signed-in session#1221
msukkari merged 7 commits into
mainfrom
msukkari/fix-oauth-linking-orphan

Conversation

@msukkari

@msukkarimsukkari commented May 22, 2026

Copy link
Copy Markdown
Contributor

Summary

OAuth providers configured with `purpose: "account_linking"` should only ever attach an identity to an existing signed-in user, never mint a new Sourcebot user. `@auth/core` does not know about this distinction and falls back to `createUser` when its session lookup returns null, which can happen when the user's session cookie expires while they are on the upstream consent screen. The result is a silent orphan `User` row and a confused user.

Add a `signIn` callback that refuses the request in that case.

Test plan

  • TypeScript build clean (`yarn workspace @sourcebot/web build`).
  • Docker image builds and boots cleanly.
  • Live negative path: sign in as Bob, click Disconnect, click Connect, wait past `AUTH_SESSION_MAX_AGE_SECONDS` on the BB consent screen, approve. Expect Sourcebot to land on the error page with no orphan User or Account row created.
  • Live positive path: sign in as Bob, click Connect, approve on BB within the session lifetime. Expect Pan Owner to link cleanly to Bob.
  • Live regression check: credentials login still works (no OAuth account on the request, signIn returns true early).

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Bug Fixes

    • OAuth account-linking now rejects sign-in attempts without an active authenticated session, preventing orphaned user accounts.
    • Credential sign-in now fails safely when an existing account lacks a stored password, avoiding invalid password checks.
  • Documentation

    • Changelog updated under Unreleased → Fixed to record these account-linking and credential behavior changes.

Review Change Stack

If a user clicks "Connect Bitbucket" and their session-token cookie is
missing or expired by the time the BB redirect arrives at our callback,
@auth/core silently falls through to createUser and mints a new orphan
User row from the OAuth profile. The orphan has no email, no UserToOrg,
and the user's session cookie gets rebound to it, leaving them on a
"request access" page.
Add a signIn callback that calls auth() and refuses the request when
the provider's purpose is account_linking and no session is present.
SSO providers and credentials login are unaffected.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitaiBot commented May 22, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

Pull request was closed or merged during review

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

Walkthrough

Adds a NextAuth callbacks.signIn handler that resolves the configured provider, treats OAuth/OIDC sign-ins with purpose: "account_linking" as account-linking attempts, calls auth() to get the current session, and rejects account-linking sign-ins when no authenticated session exists. A CHANGELOG entry documents the fix.

Changes

OAuth Account-Linking Session Validation

Layer / File(s)Summary
Credentials authorize safeguard
packages/web/src/auth.ts
In the credentials provider authorize flow, return null when an existing user has no hashedPassword, aborting credential authentication.
Sign-in callback and provider ID resolution
packages/web/src/auth.ts, CHANGELOG.md
Adds callbacks.signIn that matches account.provider to configured providers (using getEffectiveProviderId to read provider.id or provider.options.id), calls auth(), and denies sign-in for purpose: "account_linking" when auth() returns null. Updates CHANGELOG.md with a Fixed note about rejecting account-linking without a signed-in session.

Sequence Diagram

sequenceDiagram
participant Client
participant NextAuth
participant ProviderRegistry
participant AuthResolver
Client->>NextAuth: OAuth/OIDC provider callback (account)
NextAuth->>ProviderRegistry: getProviders() -> find provider for account.provider
NextAuth->>AuthResolver: auth() to resolve current session (if provider.purpose == "account_linking")
AuthResolver-->>NextAuth: session or null
NextAuth-->>Client: allow or deny sign-in (deny if account_linking && session == null)
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

Suggested reviewers

  • brendan-kellam
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately and concisely describes the main change: preventing OAuth account-linking when no signed-in session exists, which is the core objective of the PR.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch msukkari/fix-oauth-linking-orphan

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

msukkariand others added 5 commits May 21, 2026 20:59
The fix is gated behind the sso entitlement (no OAuth identity
providers are loaded in OSS deployments), so the [EE] prefix is
appropriate per CLAUDE.md.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
packages/web/src/auth.ts (1)

283-290: ⚡ Quick win

Only resolve the session for account-linking flows.

auth() runs on every sign-in attempt, but only the account_linking branch uses its result. Moving the lookup inside that branch keeps credentials/email/SSO logins off the extra session decode/DB path.

♻️ Proposed change
- const isAccountLinkingAttempt = matchingProvider?.purpose === 'account_linking';- const session = await auth();-- if (isAccountLinkingAttempt && session === null) {- return false;- }-- return true;+ if (matchingProvider?.purpose !== 'account_linking') {+ return true;+ }++ const session = await auth();+ return session !== null;
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/web/src/auth.ts` around lines 283 - 290, The code currently calls
auth() unconditionally; change it so we only call auth() when
matchingProvider?.purpose === 'account_linking' by moving the session lookup
inside that branch: compute isAccountLinkingAttempt from matchingProvider, and
if true then await auth() and return false if the session is null, otherwise
proceed to return true; remove the unconditional auth() call so
non-account_linking sign-ins avoid the extra session decode/DB path.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/web/src/auth.ts`:
- Around line 243-260: Extract a shared helper (e.g.,
getEffectiveProviderId(provider)) that returns config.options?.id ?? config.id
and replace the inline resolver in callbacks.signIn() (where matchingProvider is
computed) and in getIssuerUrlForAccount() so both paths use the same effective
provider id logic; additionally, defer calling auth() to fetch the session by
moving "const session = await auth()" behind a guard so it only runs when
matchingProvider?.purpose === 'account_linking' (instead of running
unconditionally during every sign-in).
---
Nitpick comments:
In `@packages/web/src/auth.ts`:
- Around line 283-290: The code currently calls auth() unconditionally; change
it so we only call auth() when matchingProvider?.purpose === 'account_linking'
by moving the session lookup inside that branch: compute isAccountLinkingAttempt
from matchingProvider, and if true then await auth() and return false if the
session is null, otherwise proceed to return true; remove the unconditional
auth() call so non-account_linking sign-ins avoid the extra session decode/DB
path.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 420486e4-3fea-443c-bc74-a8f7c099f806

📥 Commits

Reviewing files that changed from the base of the PR and between 18c3dab and 85af3fe.

📒 Files selected for processing (1)
  • packages/web/src/auth.ts

Comment threadpackages/web/src/auth.ts Outdated
Shared between signIn callback and getIssuerUrlForAccount. The latter previously read only the top-level provider id, which silently returned undefined for factory-based providers with an `id:` override (Bitbucket Cloud, GitHub, GitLab, Google, Okta, Keycloak, Entra, Authentik), meaning the stored issuerUrl was never resolved correctly for those accounts.
@msukkari
msukkari merged commit 987e6e4 into mainMay 22, 2026
8 of 9 checks passed
@github-actionsgithub-actionsBot mentioned this pull request May 22, 2026
@msukkari
msukkari deleted the msukkari/fix-oauth-linking-orphan branch May 22, 2026 20:55
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@msukkari
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(web): reject OAuth account-linking without a signed-in session - #1221

Merged
msukkari merged 7 commits into
mainfrom
msukkari/fix-oauth-linking-orphan
May 22, 2026
Merged

fix(web): reject OAuth account-linking without a signed-in session#1221
msukkari merged 7 commits into
mainfrom
msukkari/fix-oauth-linking-orphan

Conversation

@msukkari

@msukkarimsukkari commented May 22, 2026

Copy link
Copy Markdown
Contributor

Summary

OAuth providers configured with `purpose: "account_linking"` should only ever attach an identity to an existing signed-in user, never mint a new Sourcebot user. `@auth/core` does not know about this distinction and falls back to `createUser` when its session lookup returns null, which can happen when the user's session cookie expires while they are on the upstream consent screen. The result is a silent orphan `User` row and a confused user.

Add a `signIn` callback that refuses the request in that case.

Test plan

  • TypeScript build clean (`yarn workspace @sourcebot/web build`).
  • Docker image builds and boots cleanly.
  • Live negative path: sign in as Bob, click Disconnect, click Connect, wait past `AUTH_SESSION_MAX_AGE_SECONDS` on the BB consent screen, approve. Expect Sourcebot to land on the error page with no orphan User or Account row created.
  • Live positive path: sign in as Bob, click Connect, approve on BB within the session lifetime. Expect Pan Owner to link cleanly to Bob.
  • Live regression check: credentials login still works (no OAuth account on the request, signIn returns true early).

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Bug Fixes

    • OAuth account-linking now rejects sign-in attempts without an active authenticated session, preventing orphaned user accounts.
    • Credential sign-in now fails safely when an existing account lacks a stored password, avoiding invalid password checks.
  • Documentation

    • Changelog updated under Unreleased → Fixed to record these account-linking and credential behavior changes.

Review Change Stack

If a user clicks "Connect Bitbucket" and their session-token cookie is
missing or expired by the time the BB redirect arrives at our callback,
@auth/core silently falls through to createUser and mints a new orphan
User row from the OAuth profile. The orphan has no email, no UserToOrg,
and the user's session cookie gets rebound to it, leaving them on a
"request access" page.
Add a signIn callback that calls auth() and refuses the request when
the provider's purpose is account_linking and no session is present.
SSO providers and credentials login are unaffected.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitaiBot commented May 22, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

Pull request was closed or merged during review

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

Walkthrough

Adds a NextAuth callbacks.signIn handler that resolves the configured provider, treats OAuth/OIDC sign-ins with purpose: "account_linking" as account-linking attempts, calls auth() to get the current session, and rejects account-linking sign-ins when no authenticated session exists. A CHANGELOG entry documents the fix.

Changes

OAuth Account-Linking Session Validation

Layer / File(s)Summary
Credentials authorize safeguard
packages/web/src/auth.ts
In the credentials provider authorize flow, return null when an existing user has no hashedPassword, aborting credential authentication.
Sign-in callback and provider ID resolution
packages/web/src/auth.ts, CHANGELOG.md
Adds callbacks.signIn that matches account.provider to configured providers (using getEffectiveProviderId to read provider.id or provider.options.id), calls auth(), and denies sign-in for purpose: "account_linking" when auth() returns null. Updates CHANGELOG.md with a Fixed note about rejecting account-linking without a signed-in session.

Sequence Diagram

sequenceDiagram
participant Client
participant NextAuth
participant ProviderRegistry
participant AuthResolver
Client->>NextAuth: OAuth/OIDC provider callback (account)
NextAuth->>ProviderRegistry: getProviders() -> find provider for account.provider
NextAuth->>AuthResolver: auth() to resolve current session (if provider.purpose == "account_linking")
AuthResolver-->>NextAuth: session or null
NextAuth-->>Client: allow or deny sign-in (deny if account_linking && session == null)
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

Suggested reviewers

  • brendan-kellam
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately and concisely describes the main change: preventing OAuth account-linking when no signed-in session exists, which is the core objective of the PR.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch msukkari/fix-oauth-linking-orphan

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

msukkariand others added 5 commits May 21, 2026 20:59
The fix is gated behind the sso entitlement (no OAuth identity
providers are loaded in OSS deployments), so the [EE] prefix is
appropriate per CLAUDE.md.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
packages/web/src/auth.ts (1)

283-290: ⚡ Quick win

Only resolve the session for account-linking flows.

auth() runs on every sign-in attempt, but only the account_linking branch uses its result. Moving the lookup inside that branch keeps credentials/email/SSO logins off the extra session decode/DB path.

♻️ Proposed change
- const isAccountLinkingAttempt = matchingProvider?.purpose === 'account_linking';- const session = await auth();-- if (isAccountLinkingAttempt && session === null) {- return false;- }-- return true;+ if (matchingProvider?.purpose !== 'account_linking') {+ return true;+ }++ const session = await auth();+ return session !== null;
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/web/src/auth.ts` around lines 283 - 290, The code currently calls
auth() unconditionally; change it so we only call auth() when
matchingProvider?.purpose === 'account_linking' by moving the session lookup
inside that branch: compute isAccountLinkingAttempt from matchingProvider, and
if true then await auth() and return false if the session is null, otherwise
proceed to return true; remove the unconditional auth() call so
non-account_linking sign-ins avoid the extra session decode/DB path.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/web/src/auth.ts`:
- Around line 243-260: Extract a shared helper (e.g.,
getEffectiveProviderId(provider)) that returns config.options?.id ?? config.id
and replace the inline resolver in callbacks.signIn() (where matchingProvider is
computed) and in getIssuerUrlForAccount() so both paths use the same effective
provider id logic; additionally, defer calling auth() to fetch the session by
moving "const session = await auth()" behind a guard so it only runs when
matchingProvider?.purpose === 'account_linking' (instead of running
unconditionally during every sign-in).
---
Nitpick comments:
In `@packages/web/src/auth.ts`:
- Around line 283-290: The code currently calls auth() unconditionally; change
it so we only call auth() when matchingProvider?.purpose === 'account_linking'
by moving the session lookup inside that branch: compute isAccountLinkingAttempt
from matchingProvider, and if true then await auth() and return false if the
session is null, otherwise proceed to return true; remove the unconditional
auth() call so non-account_linking sign-ins avoid the extra session decode/DB
path.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 420486e4-3fea-443c-bc74-a8f7c099f806

📥 Commits

Reviewing files that changed from the base of the PR and between 18c3dab and 85af3fe.

📒 Files selected for processing (1)
  • packages/web/src/auth.ts

Comment threadpackages/web/src/auth.ts Outdated
Shared between signIn callback and getIssuerUrlForAccount. The latter previously read only the top-level provider id, which silently returned undefined for factory-based providers with an `id:` override (Bitbucket Cloud, GitHub, GitLab, Google, Okta, Keycloak, Entra, Authentik), meaning the stored issuerUrl was never resolved correctly for those accounts.
@msukkari
msukkari merged commit 987e6e4 into mainMay 22, 2026
8 of 9 checks passed
@github-actionsgithub-actionsBot mentioned this pull request May 22, 2026
@msukkari
msukkari deleted the msukkari/fix-oauth-linking-orphan branch May 22, 2026 20:55
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@msukkari
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix(web): reject OAuth account-linking without a signed-in session - #1221

Merged
msukkari merged 7 commits into
mainfrom
msukkari/fix-oauth-linking-orphan
May 22, 2026
Merged

fix(web): reject OAuth account-linking without a signed-in session#1221
msukkari merged 7 commits into
mainfrom
msukkari/fix-oauth-linking-orphan

Conversation

@msukkari

@msukkarimsukkari commented May 22, 2026

Copy link
Copy Markdown
Contributor

Summary

OAuth providers configured with `purpose: "account_linking"` should only ever attach an identity to an existing signed-in user, never mint a new Sourcebot user. `@auth/core` does not know about this distinction and falls back to `createUser` when its session lookup returns null, which can happen when the user's session cookie expires while they are on the upstream consent screen. The result is a silent orphan `User` row and a confused user.

Add a `signIn` callback that refuses the request in that case.

Test plan

  • TypeScript build clean (`yarn workspace @sourcebot/web build`).
  • Docker image builds and boots cleanly.
  • Live negative path: sign in as Bob, click Disconnect, click Connect, wait past `AUTH_SESSION_MAX_AGE_SECONDS` on the BB consent screen, approve. Expect Sourcebot to land on the error page with no orphan User or Account row created.
  • Live positive path: sign in as Bob, click Connect, approve on BB within the session lifetime. Expect Pan Owner to link cleanly to Bob.
  • Live regression check: credentials login still works (no OAuth account on the request, signIn returns true early).

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Bug Fixes

    • OAuth account-linking now rejects sign-in attempts without an active authenticated session, preventing orphaned user accounts.
    • Credential sign-in now fails safely when an existing account lacks a stored password, avoiding invalid password checks.
  • Documentation

    • Changelog updated under Unreleased → Fixed to record these account-linking and credential behavior changes.

Review Change Stack

If a user clicks "Connect Bitbucket" and their session-token cookie is
missing or expired by the time the BB redirect arrives at our callback,
@auth/core silently falls through to createUser and mints a new orphan
User row from the OAuth profile. The orphan has no email, no UserToOrg,
and the user's session cookie gets rebound to it, leaving them on a
"request access" page.
Add a signIn callback that calls auth() and refuses the request when
the provider's purpose is account_linking and no session is present.
SSO providers and credentials login are unaffected.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitaiBot commented May 22, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

Pull request was closed or merged during review

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

Walkthrough

Adds a NextAuth callbacks.signIn handler that resolves the configured provider, treats OAuth/OIDC sign-ins with purpose: "account_linking" as account-linking attempts, calls auth() to get the current session, and rejects account-linking sign-ins when no authenticated session exists. A CHANGELOG entry documents the fix.

Changes

OAuth Account-Linking Session Validation

Layer / File(s)Summary
Credentials authorize safeguard
packages/web/src/auth.ts
In the credentials provider authorize flow, return null when an existing user has no hashedPassword, aborting credential authentication.
Sign-in callback and provider ID resolution
packages/web/src/auth.ts, CHANGELOG.md
Adds callbacks.signIn that matches account.provider to configured providers (using getEffectiveProviderId to read provider.id or provider.options.id), calls auth(), and denies sign-in for purpose: "account_linking" when auth() returns null. Updates CHANGELOG.md with a Fixed note about rejecting account-linking without a signed-in session.

Sequence Diagram

sequenceDiagram
participant Client
participant NextAuth
participant ProviderRegistry
participant AuthResolver
Client->>NextAuth: OAuth/OIDC provider callback (account)
NextAuth->>ProviderRegistry: getProviders() -> find provider for account.provider
NextAuth->>AuthResolver: auth() to resolve current session (if provider.purpose == "account_linking")
AuthResolver-->>NextAuth: session or null
NextAuth-->>Client: allow or deny sign-in (deny if account_linking && session == null)
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

Suggested reviewers

  • brendan-kellam
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately and concisely describes the main change: preventing OAuth account-linking when no signed-in session exists, which is the core objective of the PR.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch msukkari/fix-oauth-linking-orphan

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

msukkariand others added 5 commits May 21, 2026 20:59
The fix is gated behind the sso entitlement (no OAuth identity
providers are loaded in OSS deployments), so the [EE] prefix is
appropriate per CLAUDE.md.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
packages/web/src/auth.ts (1)

283-290: ⚡ Quick win

Only resolve the session for account-linking flows.

auth() runs on every sign-in attempt, but only the account_linking branch uses its result. Moving the lookup inside that branch keeps credentials/email/SSO logins off the extra session decode/DB path.

♻️ Proposed change
- const isAccountLinkingAttempt = matchingProvider?.purpose === 'account_linking';- const session = await auth();-- if (isAccountLinkingAttempt && session === null) {- return false;- }-- return true;+ if (matchingProvider?.purpose !== 'account_linking') {+ return true;+ }++ const session = await auth();+ return session !== null;
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/web/src/auth.ts` around lines 283 - 290, The code currently calls
auth() unconditionally; change it so we only call auth() when
matchingProvider?.purpose === 'account_linking' by moving the session lookup
inside that branch: compute isAccountLinkingAttempt from matchingProvider, and
if true then await auth() and return false if the session is null, otherwise
proceed to return true; remove the unconditional auth() call so
non-account_linking sign-ins avoid the extra session decode/DB path.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/web/src/auth.ts`:
- Around line 243-260: Extract a shared helper (e.g.,
getEffectiveProviderId(provider)) that returns config.options?.id ?? config.id
and replace the inline resolver in callbacks.signIn() (where matchingProvider is
computed) and in getIssuerUrlForAccount() so both paths use the same effective
provider id logic; additionally, defer calling auth() to fetch the session by
moving "const session = await auth()" behind a guard so it only runs when
matchingProvider?.purpose === 'account_linking' (instead of running
unconditionally during every sign-in).
---
Nitpick comments:
In `@packages/web/src/auth.ts`:
- Around line 283-290: The code currently calls auth() unconditionally; change
it so we only call auth() when matchingProvider?.purpose === 'account_linking'
by moving the session lookup inside that branch: compute isAccountLinkingAttempt
from matchingProvider, and if true then await auth() and return false if the
session is null, otherwise proceed to return true; remove the unconditional
auth() call so non-account_linking sign-ins avoid the extra session decode/DB
path.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 420486e4-3fea-443c-bc74-a8f7c099f806

📥 Commits

Reviewing files that changed from the base of the PR and between 18c3dab and 85af3fe.

📒 Files selected for processing (1)
  • packages/web/src/auth.ts

Comment threadpackages/web/src/auth.ts Outdated
Shared between signIn callback and getIssuerUrlForAccount. The latter previously read only the top-level provider id, which silently returned undefined for factory-based providers with an `id:` override (Bitbucket Cloud, GitHub, GitLab, Google, Okta, Keycloak, Entra, Authentik), meaning the stored issuerUrl was never resolved correctly for those accounts.
@msukkari
msukkari merged commit 987e6e4 into mainMay 22, 2026
8 of 9 checks passed
@github-actionsgithub-actionsBot mentioned this pull request May 22, 2026
@msukkari
msukkari deleted the msukkari/fix-oauth-linking-orphan branch May 22, 2026 20:55
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@msukkari