Repository navigation
Conversation
There was a problem hiding this comment.
🟡 Changes recommended
The pinned auth revision omits a subsequent upstream fix preventing confirmation-token leakage on later error paths.
1 open finding
What changed in this PR
Hardens email login against foreign signed tokens and updates CI for Go 1.27 compatibility.
Changes:
- Bumps and vendors
go-pkgz/auth/v2. - Adds an unsubscribe-token login regression test.
- Updates golangci-lint to v2.14.0.
| File | Description |
|---|---|
backend/go.mod |
Updates auth dependency revision. |
backend/go.sum |
Updates dependency checksums. |
backend/vendor/modules.txt |
Records vendored auth revision. |
backend/vendor/github.com/go-pkgz/auth/v2/provider/verify.go |
Rejects foreign confirmation tokens. |
backend/app/cmd/server_test.go |
Tests unsubscribe-token rejection. |
.github/workflows/ci-backend.yml |
Updates backend lint version. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| github.com/alecthomas/chroma/v2 v2.27.0 | ||
| github.com/didip/tollbooth/v8 v8.0.1 | ||
| github.com/go-pkgz/auth/v2 v2.3.0 | ||
| github.com/go-pkgz/auth/v2 v2.3.1-0.20261011064528-6c9fe1f3f7ce |
There was a problem hiding this comment.
Repinned to cecb18d (current master, which includes 2062119) in 670ce71; module and vendor files are regenerated.
|
go-pkgz/auth v2.3.1 is out, tagged at the same commit this PR pins ( |
The email login accepted any token carrying a user and address handshake signed with the shared secret. Unsubscribe links carry such a token for every notified user, valid for a century, so anyone holding one could sign in with the email identity for that address. The auth master now accepts only the email provider's own confirmation tokens; no release with the change is tagged yet, so the module points at that commit.
The previous pin still logged the request, confirmation token included, when verify login failed after accepting the token: on a bad handshake, an avatar save error, a token id error or a session token error. The current master passes the redacted request on those paths too.
v2.3.1 is tagged at the commit the module was already pinned to, so the vendored code stays the same and only the version moves to the release.
|
Rebased onto master and moved |

Previously,
/auth/email/loginaccepted any token carrying auser::addresshandshake signed with the shared secret. The token in unsubscribe links is such a token, valid for a century, so anyone holding an unsubscribe link, for example from a forwarded notification, could sign in with the email identity for that address.After this change,
github.com/go-pkgz/auth/v2is at v2.3.1, which requires a signed handshake token carrying the email provider's name (go-pkgz/auth#319) and no longer logs the token on the login error paths.TestServerApp_UnsubscribeTokenIsNotALoginmints the token through the server's own unsubscribe token generator and expects the login to be refused; with auth v2.3.0 it gets a session instead.