fix(auth) : bind Sudloh sessions and stop OAuth redirect loops
CI / Verify (push) Successful in 1m31s
CI / Build immutable images and deploy (push) Successful in 2m4s

This commit is contained in:
2026-10-06 14:28:59 +07:00 Unverified
parent 2f69115a91
commit 445865bf42
13 changed files with 212 additions and 21 deletions
+77
View File
@@ -0,0 +1,77 @@
import { describe, expect, it, vi } from "vitest";
import { betterAuth } from "better-auth";
import { memoryAdapter } from "better-auth/adapters/memory";
import { genericOAuth } from "better-auth/plugins";
import { isSudlohCallback } from "./sudloh-callback";
const origin = "https://guide.test";
function createReplica(database: Record<string, Record<string, unknown>[]>, onSession: (sessionId: string) => void) {
return betterAuth({
baseURL: origin,
secret: "a-shared-test-secret-with-enough-entropy-123",
database: memoryAdapter(database),
rateLimit: { enabled: false },
databaseHooks: { session: { create: { after: async (
session: { id: string }, context: { path: string; params?: { id?: string } } | null,
) => {
if (isSudlohCallback(context)) onSession(session.id);
} } } },
plugins: [genericOAuth({ config: [{
providerId: "sudloh",
clientId: "test-client",
clientSecret: "test-secret",
authorizationUrl: "https://account.test/authorize",
tokenUrl: "https://account.test/token",
getToken: async () => ({ accessToken: "test-access-token", accessTokenExpiresAt: new Date(Date.now() + 3600_000) }),
getUserInfo: async () => ({ id: "test-subject", email: "[email protected]",
emailVerified: true, name: "Test User" }),
}] })],
});
}
describe("Sudloh OAuth callback", () => {
it("completes across replicas, binds the Guide session, and consumes state once", async () => {
const database = { user: [], session: [], account: [], verification: [] };
const bind = vi.fn();
const first = createReplica(database, bind);
const second = createReplica(database, bind);
const start = await first.handler(new Request(`${origin}/api/auth/sign-in/social`, {
method: "POST", headers: { Origin: origin, "Content-Type": "application/json" },
body: JSON.stringify({ provider: "sudloh", callbackURL: "/profile" }),
}));
expect(start.status).toBe(200);
const authorization = new URL((await start.json()).url);
expect(authorization.searchParams.get("code_challenge_method")).toBe("S256");
expect(authorization.searchParams.get("code_challenge")).toBeTruthy();
const stateCookie = start.headers.get("set-cookie")?.split(";", 1)[0];
expect(stateCookie).toBeTruthy();
const callbackURL = new URL(`${origin}/api/auth/callback/sudloh`);
callbackURL.searchParams.set("code", "test-code");
callbackURL.searchParams.set("state", authorization.searchParams.get("state")!);
const callback = await second.handler(new Request(callbackURL, {
headers: { Cookie: stateCookie! },
}));
expect(callback.status).toBe(302);
expect(callback.headers.get("location")).toBe("/profile");
expect(bind).toHaveBeenCalledOnce();
const sessionCookie = callback.headers.getSetCookie()
.find((cookie) => cookie.includes("session_token="))?.split(";", 1)[0];
const session = await second.api.getSession({ headers: new Headers({ Cookie: sessionCookie! }) });
expect(session?.user.email).toBe("[email protected]");
const replay = await first.handler(new Request(callbackURL, {
headers: { Cookie: stateCookie! },
}));
expect(replay.headers.get("location")).toContain("state_mismatch");
expect(bind).toHaveBeenCalledOnce();
});
it("rejects a callback without state before exchanging a code", async () => {
const bind = vi.fn();
const auth = createReplica({ user: [], session: [], account: [], verification: [] }, bind);
const response = await auth.handler(new Request(`${origin}/api/auth/callback/sudloh?code=test-code`));
expect(response.status).toBe(302);
expect(response.headers.get("location")).toContain("state_not_found");
expect(bind).not.toHaveBeenCalled();
});
});
+9 -2
View File
@@ -13,7 +13,7 @@ vi.mock("better-auth/plugins", () => ({ admin: (options: unknown) => options, ca
emailOTP: (options: unknown) => ({ id: "email-otp", options }) }));
vi.mock("./sudloh", () => ({ bindSudlohSession: sudloh.bind, validateSudlohSession: sudloh.validate }));
const envNames = ["NODE_ENV", "DATABASE_URL", "BETTER_AUTH_URL", "BETTER_AUTH_SECRET", "BUZZ_DEMO_MODE", "RESEND_API_KEY", "SUDLOH_OIDC_CLIENT_ID", "SUDLOH_OIDC_CLIENT_SECRET", "SUDLOH_OIDC_REDIRECT_URI", "SUDLOH_OIDC_ISSUER", "SUDLOH_OIDC_ONLY"] as const;
const envNames = ["NODE_ENV", "DATABASE_URL", "BETTER_AUTH_URL", "BETTER_AUTH_SECRET", "BUZZ_DEMO_MODE", "RESEND_API_KEY", "SUDLOH_OIDC_CLIENT_ID", "SUDLOH_OIDC_CLIENT_SECRET", "SUDLOH_OIDC_REDIRECT_URI", "SUDLOH_OIDC_ISSUER", "SUDLOH_OIDC_ONLY", "TRUSTED_CLIENT_IP_HEADER"] as const;
const testEnv = process.env as Record<string, string | undefined>;
const originalEnv = envNames.map((name) => testEnv[name]);
@@ -32,6 +32,7 @@ beforeEach(() => {
delete testEnv.SUDLOH_OIDC_REDIRECT_URI;
delete testEnv.SUDLOH_OIDC_ISSUER;
delete testEnv.SUDLOH_OIDC_ONLY;
delete testEnv.TRUSTED_CLIENT_IP_HEADER;
});
afterEach(() => {
envNames.forEach((name, index) => {
@@ -91,13 +92,19 @@ describe("actual administrator session boundary", () => {
testEnv.SUDLOH_OIDC_CLIENT_SECRET = "secret";
testEnv.SUDLOH_OIDC_REDIRECT_URI = "https://guide.example.test/api/auth/callback/sudloh";
testEnv.SUDLOH_OIDC_ONLY = "true";
testEnv.TRUSTED_CLIENT_IP_HEADER = "x-forwarded-for";
(await import("./server")).getAuth();
const options = mocks.auth.mock.calls.at(-1)![0];
expect(options.advanced.ipAddress.ipAddressHeaders).toEqual(["x-forwarded-for"]);
expect(options.emailAndPassword).toMatchObject({ enabled: false, disableSignUp: true });
expect(options.plugins.some((plugin: { id?: string }) => plugin.id === "email-otp")).toBe(false);
await options.databaseHooks.session.create.after({ id: "guide-session", userId: "user-1" },
{ path: "/callback/sudloh" });
{ path: "/callback/:id", params: { id: "sudloh" } });
expect(sudloh.bind).toHaveBeenCalledWith("user-1", "guide-session");
sudloh.bind.mockClear();
await options.databaseHooks.session.create.after({ id: "other-session", userId: "user-1" },
{ path: "/callback/:id", params: { id: "other" } });
expect(sudloh.bind).not.toHaveBeenCalled();
});
it("denies a revoked Sudloh session", async () => {
testEnv.SUDLOH_OIDC_CLIENT_ID = "client";
+5 -2
View File
@@ -20,6 +20,7 @@ import { HttpError } from "@/lib/security/http";
import { consumeRateLimit } from "@/lib/security/rate-limit";
import { sendAuthEmail } from "./email";
import { bindSudlohSession, validateSudlohSession } from "./sudloh";
import { isSudlohCallback } from "./sudloh-callback";
function required(name: string): string {
const value = process.env[name];
@@ -65,9 +66,11 @@ function createAuth() {
transaction: true,
}),
...(oidcOnly ? { databaseHooks: { session: { create: { after: async (
session: { id: string; userId: string }, context: { path: string } | null,
session: { id: string; userId: string },
context: { path: string; params?: { id?: string } } | null,
) => {
if (context?.path.endsWith("/callback/sudloh")) await bindSudlohSession(session.userId, session.id);
if (isSudlohCallback(context))
await bindSudlohSession(session.userId, session.id);
} } } } } : {}),
baseURL: required("BETTER_AUTH_URL"),
trustedOrigins: process.env.BETTER_AUTH_TRUSTED_ORIGINS
+3
View File
@@ -0,0 +1,3 @@
export function isSudlohCallback(context: { path: string; params?: { id?: string } } | null): boolean {
return context?.path === "/callback/:id" && context.params?.id === "sudloh";
}
+42
View File
@@ -0,0 +1,42 @@
import { afterEach, beforeEach, describe, expect, it, vi } from "vitest";
import { claimAutomaticSudlohSignIn, markSudlohSignInAttempt, sudlohStartErrorMessage } from "./sudloh-redirect";
const values = new Map<string, string>();
beforeEach(() => {
values.clear();
vi.stubGlobal("sessionStorage", {
getItem: (key: string) => values.get(key) ?? null,
setItem: (key: string, value: string) => { values.set(key, value); },
});
vi.spyOn(Date, "now").mockReturnValue(1_000_000);
});
afterEach(() => {
vi.restoreAllMocks();
vi.unstubAllGlobals();
});
describe("Sudloh redirect guard", () => {
it("starts once and stops automatic redirects when login is revisited", () => {
expect(claimAutomaticSudlohSignIn()).toBe(true);
expect(claimAutomaticSudlohSignIn()).toBe(false);
vi.spyOn(Date, "now").mockReturnValue(1_000_000 + 5 * 60_000);
expect(claimAutomaticSudlohSignIn()).toBe(true);
});
it("keeps logout from immediately starting another sign-in", () => {
markSudlohSignInAttempt();
expect(claimAutomaticSudlohSignIn()).toBe(false);
});
it("requires a manual start when browser storage is unavailable", () => {
vi.stubGlobal("sessionStorage", { getItem: () => { throw new Error("blocked"); } });
expect(claimAutomaticSudlohSignIn()).toBe(false);
});
it("explains a rate limit without leaking the provider response", () => {
expect(sudlohStartErrorMessage(429)).toContain("รอสักครู่");
expect(sudlohStartErrorMessage(503)).not.toContain("รอสักครู่");
});
});
+24
View File
@@ -0,0 +1,24 @@
const attemptKey = "sudloh-oidc-last-start";
const attemptWindowMs = 5 * 60 * 1000;
export function sudlohStartErrorMessage(status?: number): string {
return status === 429
? "ลองเข้าสู่ระบบบ่อยเกินไป กรุณารอสักครู่แล้วลองอีกครั้ง"
: "ไม่สามารถเริ่มเข้าสู่ระบบได้ กรุณาลองอีกครั้ง";
}
export function markSudlohSignInAttempt() {
try { sessionStorage.setItem(attemptKey, String(Date.now())); }
catch { /* A manual retry remains available when storage is blocked. */ }
}
export function claimAutomaticSudlohSignIn(): boolean {
try {
const lastAttempt = Number(sessionStorage.getItem(attemptKey));
if (lastAttempt > 0 && Date.now() - lastAttempt < attemptWindowMs) return false;
markSudlohSignInAttempt();
return true;
} catch {
return false;
}
}
+6
View File
@@ -48,6 +48,12 @@ function provider(active: boolean, profileSub = "sub-1") {
}
describe("Sudloh session validation", () => {
it("rejects a new Guide session when the callback did not bind it", async () => {
rows.push([account]);
expect(await validateSudlohSession("user-1", "session-1")).toBe(false);
expect(removeSession).toHaveBeenCalledOnce();
});
it("binds the callback token to its Guide session and caches a verified check", async () => {
rows.push([account]);
await bindSudlohSession("user-1", "session-1");