Skip to content

Fix OAuth state across Render restarts - #4

Merged
beme08 merged 1 commit into
mainfrom
agent/fix-oauth-state
Jul 14, 2026
Merged

beme08 merged 1 commit into
mainfrom
agent/fix-oauth-state

Conversation

@beme08

@beme08 beme08 commented Jul 14, 2026

Copy link
Copy Markdown
Owner

What changed

  • store OAuth state and the PKCE verifier in a signed, short-lived HttpOnly cookie
  • validate the cookie signature, state, and ten-minute expiry at callback time
  • add tampering and wrong-state regression coverage
  • document the restart-safe OAuth behavior

Why

Render process restarts or instance changes erased the in-memory PKCE verifier between login and GitHub's callback, causing valid users to receive Invalid OAuth state.

Impact

An authorization in progress now survives a Render process change without weakening the existing state or PKCE checks. Established user sessions remain server-side and unchanged.

Validation

  • npm test — 9 passed
  • npm run build — passed
  • npm run smoke — passed
  • git diff --check — passed

@beme08
beme08 merged commit 61e7f8d into main Jul 14, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant