feat(auth): add native Google and GitHub OAuth login for Dashboard - #15153
Open
trinitynexusai wants to merge 2 commits into
Open
trinitynexusai wants to merge 2 commits into
trinitynexusai wants to merge 2 commits into
Conversation
…efault - classify /api/auth/google/ and /api/auth/github/ as public routes (they were MANAGEMENT, so requireLogin answered 401 before the login handler ran) + classifyRoute regression test - deny-by-default allowlist: an empty list or a bare "*" admits nobody and a provider stays disabled until AUTH_ALLOWED_EMAILS is non-empty; drop the generic GOOGLE_/GITHUB_CLIENT_ID fallbacks; GitHub usernames only match bare username entries - GitHub: no fallback to the unverified public profile e-mail (fail closed) - redirect_uri/redirect origin use Host only (no X-Forwarded-Host); redirect paths from settings must be same-origin absolute paths; OAuth state comes from crypto.randomUUID() only - login routes answer through errorResponse(); callbacks split into helpers, no `any` - restore the oidcRedirectPath default dropped by the PR; remove PULL_REQUEST.md from the root - settingsSchemas: add the social-login keys; GET/PATCH /api/settings never return the client secrets; the new keys are password-gated security settings - i18n: login keys in all locales, error strings through t() - document AUTH_GOOGLE_*, AUTH_GITHUB_*, AUTH_ALLOWED_EMAILS, AUTH_DISABLE_PASSWORD_LOGIN Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds native Google OAuth 2.0 ("Continue with Google") and GitHub OAuth ("Continue with GitHub") authentication support to the OmniRoute management dashboard.
Highlights:
fetch,crypto,URL) and the existingjoselibrary already bundled in OmniRoute.statenonces stored in short-lived HTTP-only cookies (maxAge: 600) and validated viatimingSafeCompare(constant-time equality) to defeat timing attacks (GHSA-7434-6q4c-33fh).email_verified: truefor Google accounts and checks for verified primary emails for GitHub accounts before authorizing session issuance.AUTH_ALLOWED_EMAILS(comma-separated email list, domain wildcards like*@company.com, or GitHub usernames). Defaults to permissive if unconfigured (matching self-hosted single-admin expectations).auth_tokenJWT carryingauthenticated: truesigned withJWT_SECRETthroughverifyDashboardSessionToken/createDashboardSessionJwt.src/app/login/page.tsxwith localized strings (en,pt-BR) and an optional separator (or/ou), fully preserving password login and enterprise OIDC coexistence.AUTH_DISABLE_PASSWORD_LOGIN=truewhen operators wish to enforce SSO-only access.Related Issues
Validation
#13298dashboard session verifier source guard: zero regressionsTests Added Or Updated
tests/unit/social-oauth.test.ts:timingSafeCompareconstant-time string comparisonisEmailAllowedallowlist parsing, wildcard matching, case-insensitivitygetGoogleOAuthConfigandgetGitHubOAuthConfigenvironment and settings resolutiongetRequestOriginhost and forwarded proto derivationcreateDashboardSessionJwtminting and validation throughverifyDashboardSessionTokentests/unit/social-oauth-routes.test.ts:GET /api/auth/google/login: Configuration guard, authorization URL construction, and state cookie settingGET /api/auth/google/callback: Code exchange, state mismatch defense, email allowlist blocking, and session issuanceGET /api/auth/github/login: Redirect to GitHub authorize and state cookie generationGET /api/auth/github/callback: Token exchange, verified email resolution, allowlist filtering, and session cookie mintingtests/unit/dashboard-session-verifier-source-guard.test.ts: Re-validated 8/8 tests passing.Coverage Notes
src/lib/auth/socialOAuth.tsis 100% covered by unit tests.src/app/api/auth/google/andsrc/app/api/auth/github/are covered with simulated provider responses and cookie capture test seams (*Internals.getCookieStore).Reviewer Notes
AUTH_GOOGLE_CLIENT_ID/GOOGLE_CLIENT_IDAUTH_GOOGLE_CLIENT_SECRET/GOOGLE_CLIENT_SECRETAUTH_GITHUB_CLIENT_ID/GITHUB_CLIENT_IDAUTH_GITHUB_CLIENT_SECRET/GITHUB_CLIENT_SECRETAUTH_ALLOWED_EMAILS(optional comma-separated list of allowed emails or wildcard domains)AUTH_DISABLE_PASSWORD_LOGIN(optional boolean,truedisables password login form)settingstable (googleClientId,googleClientSecret,githubClientId,githubClientSecret), where secrets are automatically encrypted viaSTORAGE_ENCRYPTION_KEY.