fix(auth) : bind Sudloh sessions and stop OAuth redirect loops
This commit is contained in:
@@ -0,0 +1,77 @@
|
||||
import { describe, expect, it, vi } from "vitest";
|
||||
import { betterAuth } from "better-auth";
|
||||
import { memoryAdapter } from "better-auth/adapters/memory";
|
||||
import { genericOAuth } from "better-auth/plugins";
|
||||
import { isSudlohCallback } from "./sudloh-callback";
|
||||
|
||||
const origin = "https://guide.test";
|
||||
|
||||
function createReplica(database: Record<string, Record<string, unknown>[]>, onSession: (sessionId: string) => void) {
|
||||
return betterAuth({
|
||||
baseURL: origin,
|
||||
secret: "a-shared-test-secret-with-enough-entropy-123",
|
||||
database: memoryAdapter(database),
|
||||
rateLimit: { enabled: false },
|
||||
databaseHooks: { session: { create: { after: async (
|
||||
session: { id: string }, context: { path: string; params?: { id?: string } } | null,
|
||||
) => {
|
||||
if (isSudlohCallback(context)) onSession(session.id);
|
||||
} } } },
|
||||
plugins: [genericOAuth({ config: [{
|
||||
providerId: "sudloh",
|
||||
clientId: "test-client",
|
||||
clientSecret: "test-secret",
|
||||
authorizationUrl: "https://account.test/authorize",
|
||||
tokenUrl: "https://account.test/token",
|
||||
getToken: async () => ({ accessToken: "test-access-token", accessTokenExpiresAt: new Date(Date.now() + 3600_000) }),
|
||||
getUserInfo: async () => ({ id: "test-subject", email: "[email protected]",
|
||||
emailVerified: true, name: "Test User" }),
|
||||
}] })],
|
||||
});
|
||||
}
|
||||
|
||||
describe("Sudloh OAuth callback", () => {
|
||||
it("completes across replicas, binds the Guide session, and consumes state once", async () => {
|
||||
const database = { user: [], session: [], account: [], verification: [] };
|
||||
const bind = vi.fn();
|
||||
const first = createReplica(database, bind);
|
||||
const second = createReplica(database, bind);
|
||||
const start = await first.handler(new Request(`${origin}/api/auth/sign-in/social`, {
|
||||
method: "POST", headers: { Origin: origin, "Content-Type": "application/json" },
|
||||
body: JSON.stringify({ provider: "sudloh", callbackURL: "/profile" }),
|
||||
}));
|
||||
expect(start.status).toBe(200);
|
||||
const authorization = new URL((await start.json()).url);
|
||||
expect(authorization.searchParams.get("code_challenge_method")).toBe("S256");
|
||||
expect(authorization.searchParams.get("code_challenge")).toBeTruthy();
|
||||
const stateCookie = start.headers.get("set-cookie")?.split(";", 1)[0];
|
||||
expect(stateCookie).toBeTruthy();
|
||||
const callbackURL = new URL(`${origin}/api/auth/callback/sudloh`);
|
||||
callbackURL.searchParams.set("code", "test-code");
|
||||
callbackURL.searchParams.set("state", authorization.searchParams.get("state")!);
|
||||
const callback = await second.handler(new Request(callbackURL, {
|
||||
headers: { Cookie: stateCookie! },
|
||||
}));
|
||||
expect(callback.status).toBe(302);
|
||||
expect(callback.headers.get("location")).toBe("/profile");
|
||||
expect(bind).toHaveBeenCalledOnce();
|
||||
const sessionCookie = callback.headers.getSetCookie()
|
||||
.find((cookie) => cookie.includes("session_token="))?.split(";", 1)[0];
|
||||
const session = await second.api.getSession({ headers: new Headers({ Cookie: sessionCookie! }) });
|
||||
expect(session?.user.email).toBe("[email protected]");
|
||||
const replay = await first.handler(new Request(callbackURL, {
|
||||
headers: { Cookie: stateCookie! },
|
||||
}));
|
||||
expect(replay.headers.get("location")).toContain("state_mismatch");
|
||||
expect(bind).toHaveBeenCalledOnce();
|
||||
});
|
||||
|
||||
it("rejects a callback without state before exchanging a code", async () => {
|
||||
const bind = vi.fn();
|
||||
const auth = createReplica({ user: [], session: [], account: [], verification: [] }, bind);
|
||||
const response = await auth.handler(new Request(`${origin}/api/auth/callback/sudloh?code=test-code`));
|
||||
expect(response.status).toBe(302);
|
||||
expect(response.headers.get("location")).toContain("state_not_found");
|
||||
expect(bind).not.toHaveBeenCalled();
|
||||
});
|
||||
});
|
||||
@@ -13,7 +13,7 @@ vi.mock("better-auth/plugins", () => ({ admin: (options: unknown) => options, ca
|
||||
emailOTP: (options: unknown) => ({ id: "email-otp", options }) }));
|
||||
vi.mock("./sudloh", () => ({ bindSudlohSession: sudloh.bind, validateSudlohSession: sudloh.validate }));
|
||||
|
||||
const envNames = ["NODE_ENV", "DATABASE_URL", "BETTER_AUTH_URL", "BETTER_AUTH_SECRET", "BUZZ_DEMO_MODE", "RESEND_API_KEY", "SUDLOH_OIDC_CLIENT_ID", "SUDLOH_OIDC_CLIENT_SECRET", "SUDLOH_OIDC_REDIRECT_URI", "SUDLOH_OIDC_ISSUER", "SUDLOH_OIDC_ONLY"] as const;
|
||||
const envNames = ["NODE_ENV", "DATABASE_URL", "BETTER_AUTH_URL", "BETTER_AUTH_SECRET", "BUZZ_DEMO_MODE", "RESEND_API_KEY", "SUDLOH_OIDC_CLIENT_ID", "SUDLOH_OIDC_CLIENT_SECRET", "SUDLOH_OIDC_REDIRECT_URI", "SUDLOH_OIDC_ISSUER", "SUDLOH_OIDC_ONLY", "TRUSTED_CLIENT_IP_HEADER"] as const;
|
||||
const testEnv = process.env as Record<string, string | undefined>;
|
||||
const originalEnv = envNames.map((name) => testEnv[name]);
|
||||
|
||||
@@ -32,6 +32,7 @@ beforeEach(() => {
|
||||
delete testEnv.SUDLOH_OIDC_REDIRECT_URI;
|
||||
delete testEnv.SUDLOH_OIDC_ISSUER;
|
||||
delete testEnv.SUDLOH_OIDC_ONLY;
|
||||
delete testEnv.TRUSTED_CLIENT_IP_HEADER;
|
||||
});
|
||||
afterEach(() => {
|
||||
envNames.forEach((name, index) => {
|
||||
@@ -91,13 +92,19 @@ describe("actual administrator session boundary", () => {
|
||||
testEnv.SUDLOH_OIDC_CLIENT_SECRET = "secret";
|
||||
testEnv.SUDLOH_OIDC_REDIRECT_URI = "https://guide.example.test/api/auth/callback/sudloh";
|
||||
testEnv.SUDLOH_OIDC_ONLY = "true";
|
||||
testEnv.TRUSTED_CLIENT_IP_HEADER = "x-forwarded-for";
|
||||
(await import("./server")).getAuth();
|
||||
const options = mocks.auth.mock.calls.at(-1)![0];
|
||||
expect(options.advanced.ipAddress.ipAddressHeaders).toEqual(["x-forwarded-for"]);
|
||||
expect(options.emailAndPassword).toMatchObject({ enabled: false, disableSignUp: true });
|
||||
expect(options.plugins.some((plugin: { id?: string }) => plugin.id === "email-otp")).toBe(false);
|
||||
await options.databaseHooks.session.create.after({ id: "guide-session", userId: "user-1" },
|
||||
{ path: "/callback/sudloh" });
|
||||
{ path: "/callback/:id", params: { id: "sudloh" } });
|
||||
expect(sudloh.bind).toHaveBeenCalledWith("user-1", "guide-session");
|
||||
sudloh.bind.mockClear();
|
||||
await options.databaseHooks.session.create.after({ id: "other-session", userId: "user-1" },
|
||||
{ path: "/callback/:id", params: { id: "other" } });
|
||||
expect(sudloh.bind).not.toHaveBeenCalled();
|
||||
});
|
||||
it("denies a revoked Sudloh session", async () => {
|
||||
testEnv.SUDLOH_OIDC_CLIENT_ID = "client";
|
||||
|
||||
+5
-2
@@ -20,6 +20,7 @@ import { HttpError } from "@/lib/security/http";
|
||||
import { consumeRateLimit } from "@/lib/security/rate-limit";
|
||||
import { sendAuthEmail } from "./email";
|
||||
import { bindSudlohSession, validateSudlohSession } from "./sudloh";
|
||||
import { isSudlohCallback } from "./sudloh-callback";
|
||||
|
||||
function required(name: string): string {
|
||||
const value = process.env[name];
|
||||
@@ -65,9 +66,11 @@ function createAuth() {
|
||||
transaction: true,
|
||||
}),
|
||||
...(oidcOnly ? { databaseHooks: { session: { create: { after: async (
|
||||
session: { id: string; userId: string }, context: { path: string } | null,
|
||||
session: { id: string; userId: string },
|
||||
context: { path: string; params?: { id?: string } } | null,
|
||||
) => {
|
||||
if (context?.path.endsWith("/callback/sudloh")) await bindSudlohSession(session.userId, session.id);
|
||||
if (isSudlohCallback(context))
|
||||
await bindSudlohSession(session.userId, session.id);
|
||||
} } } } } : {}),
|
||||
baseURL: required("BETTER_AUTH_URL"),
|
||||
trustedOrigins: process.env.BETTER_AUTH_TRUSTED_ORIGINS
|
||||
|
||||
@@ -0,0 +1,3 @@
|
||||
export function isSudlohCallback(context: { path: string; params?: { id?: string } } | null): boolean {
|
||||
return context?.path === "/callback/:id" && context.params?.id === "sudloh";
|
||||
}
|
||||
@@ -0,0 +1,42 @@
|
||||
import { afterEach, beforeEach, describe, expect, it, vi } from "vitest";
|
||||
import { claimAutomaticSudlohSignIn, markSudlohSignInAttempt, sudlohStartErrorMessage } from "./sudloh-redirect";
|
||||
|
||||
const values = new Map<string, string>();
|
||||
|
||||
beforeEach(() => {
|
||||
values.clear();
|
||||
vi.stubGlobal("sessionStorage", {
|
||||
getItem: (key: string) => values.get(key) ?? null,
|
||||
setItem: (key: string, value: string) => { values.set(key, value); },
|
||||
});
|
||||
vi.spyOn(Date, "now").mockReturnValue(1_000_000);
|
||||
});
|
||||
|
||||
afterEach(() => {
|
||||
vi.restoreAllMocks();
|
||||
vi.unstubAllGlobals();
|
||||
});
|
||||
|
||||
describe("Sudloh redirect guard", () => {
|
||||
it("starts once and stops automatic redirects when login is revisited", () => {
|
||||
expect(claimAutomaticSudlohSignIn()).toBe(true);
|
||||
expect(claimAutomaticSudlohSignIn()).toBe(false);
|
||||
vi.spyOn(Date, "now").mockReturnValue(1_000_000 + 5 * 60_000);
|
||||
expect(claimAutomaticSudlohSignIn()).toBe(true);
|
||||
});
|
||||
|
||||
it("keeps logout from immediately starting another sign-in", () => {
|
||||
markSudlohSignInAttempt();
|
||||
expect(claimAutomaticSudlohSignIn()).toBe(false);
|
||||
});
|
||||
|
||||
it("requires a manual start when browser storage is unavailable", () => {
|
||||
vi.stubGlobal("sessionStorage", { getItem: () => { throw new Error("blocked"); } });
|
||||
expect(claimAutomaticSudlohSignIn()).toBe(false);
|
||||
});
|
||||
|
||||
it("explains a rate limit without leaking the provider response", () => {
|
||||
expect(sudlohStartErrorMessage(429)).toContain("รอสักครู่");
|
||||
expect(sudlohStartErrorMessage(503)).not.toContain("รอสักครู่");
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,24 @@
|
||||
const attemptKey = "sudloh-oidc-last-start";
|
||||
const attemptWindowMs = 5 * 60 * 1000;
|
||||
|
||||
export function sudlohStartErrorMessage(status?: number): string {
|
||||
return status === 429
|
||||
? "ลองเข้าสู่ระบบบ่อยเกินไป กรุณารอสักครู่แล้วลองอีกครั้ง"
|
||||
: "ไม่สามารถเริ่มเข้าสู่ระบบได้ กรุณาลองอีกครั้ง";
|
||||
}
|
||||
|
||||
export function markSudlohSignInAttempt() {
|
||||
try { sessionStorage.setItem(attemptKey, String(Date.now())); }
|
||||
catch { /* A manual retry remains available when storage is blocked. */ }
|
||||
}
|
||||
|
||||
export function claimAutomaticSudlohSignIn(): boolean {
|
||||
try {
|
||||
const lastAttempt = Number(sessionStorage.getItem(attemptKey));
|
||||
if (lastAttempt > 0 && Date.now() - lastAttempt < attemptWindowMs) return false;
|
||||
markSudlohSignInAttempt();
|
||||
return true;
|
||||
} catch {
|
||||
return false;
|
||||
}
|
||||
}
|
||||
@@ -48,6 +48,12 @@ function provider(active: boolean, profileSub = "sub-1") {
|
||||
}
|
||||
|
||||
describe("Sudloh session validation", () => {
|
||||
it("rejects a new Guide session when the callback did not bind it", async () => {
|
||||
rows.push([account]);
|
||||
expect(await validateSudlohSession("user-1", "session-1")).toBe(false);
|
||||
expect(removeSession).toHaveBeenCalledOnce();
|
||||
});
|
||||
|
||||
it("binds the callback token to its Guide session and caches a verified check", async () => {
|
||||
rows.push([account]);
|
||||
await bindSudlohSession("user-1", "session-1");
|
||||
|
||||
Reference in New Issue
Block a user