Skip to content

Bump go-pkgz/auth to reject foreign tokens in email login - #2265

Open
paskal wants to merge 3 commits into
masterfrom
bump-auth
Open

paskal wants to merge 3 commits into
masterfrom
bump-auth

Conversation

@paskal

@paskal paskal commented Oct 11, 2026 •

Copy link
Copy Markdown
Collaborator

Previously, /auth/email/login accepted any token carrying a user::address handshake signed with the shared secret. The token in unsubscribe links is such a token, valid for a century, so anyone holding an unsubscribe link, for example from a forwarded notification, could sign in with the email identity for that address.

After this change, github.com/go-pkgz/auth/v2 is at v2.3.1, which requires a signed handshake token carrying the email provider's name (go-pkgz/auth#319) and no longer logs the token on the login error paths.

TestServerApp_UnsubscribeTokenIsNotALogin mints the token through the server's own unsubscribe token generator and expects the login to be refused; with auth v2.3.0 it gets a session instead.

Copilot AI balanced review requested due to automatic review settings October 11, 2026 06:58
@paskal
paskal requested a review from umputun as a code owner October 11, 2026 06:58

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The pinned auth revision omits a subsequent upstream fix preventing confirmation-token leakage on later error paths.

1 open finding
What changed in this PR

Hardens email login against foreign signed tokens and updates CI for Go 1.27 compatibility.

Changes:

  • Bumps and vendors go-pkgz/auth/v2.
  • Adds an unsubscribe-token login regression test.
  • Updates golangci-lint to v2.14.0.
File Description
backend/​go.mod Updates auth dependency revision.
backend/​go.sum Updates dependency checksums.
backend/​vendor/​modules.txt Records vendored auth revision.
backend/​vendor/​github.com/​go-pkgz/​auth/​v2/​provider/​verify.go Rejects foreign confirmation tokens.
backend/​app/​cmd/​server_test.go Tests unsubscribe-token rejection.
.github/​workflows/​ci-backend.yml Updates backend lint version.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread backend/go.mod Outdated
github.com/alecthomas/chroma/v2 v2.27.0
github.com/didip/tollbooth/v8 v8.0.1
github.com/go-pkgz/auth/v2 v2.3.0
github.com/go-pkgz/auth/v2 v2.3.1-0.20261011064528-6c9fe1f3f7ce

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Repinned to cecb18d (current master, which includes 2062119) in 670ce71; module and vendor files are regenerated.

umputun
umputun previously approved these changes Oct 11, 2026

@umputun umputun left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm. #2262 went in first and changes the same place in backend/app/cmd/server_test.go, so this one conflicts now and needs a rebase.

@umputun

umputun commented Oct 11, 2026

Copy link
Copy Markdown
Owner

go-pkgz/auth v2.3.1 is out, tagged at the same commit this PR pins (cecb18d). Pls move backend/go.mod to the tag while rebasing.

The email login accepted any token carrying a user and address
handshake signed with the shared secret. Unsubscribe links carry such a
token for every notified user, valid for a century, so anyone holding
one could sign in with the email identity for that address. The auth
master now accepts only the email provider's own confirmation tokens;
no release with the change is tagged yet, so the module points at that
commit.
The previous pin still logged the request, confirmation token included,
when verify login failed after accepting the token: on a bad handshake,
an avatar save error, a token id error or a session token error. The
current master passes the redacted request on those paths too.
v2.3.1 is tagged at the commit the module was already pinned to, so the
vendored code stays the same and only the version moves to the release.
@paskal

paskal commented Oct 11, 2026

Copy link
Copy Markdown
Collaborator Author

Rebased onto master and moved backend/go.mod to v2.3.1. The tag points at the commit the branch was already pinned to, so the vendored code is unchanged. The golangci-lint commit dropped out, as master already has it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants