Skip to content

fix(server): reject future-dated OAuth state tokens - #330

Open
tahodev wants to merge 1 commit into
wordbricks:mainfrom
tahodev:fix/oauth-state-future-timestamp
Open

tahodev wants to merge 1 commit into
wordbricks:mainfrom
tahodev:fix/oauth-state-future-timestamp

Conversation

@tahodev

@tahodev tahodev commented Sep 25, 2026

Copy link
Copy Markdown

What

Reject signed OAuth state tokens whose timestamp is non-finite or ahead of the current time. Add a regression test for a state created one second in the future.

Why

The existing check rejected only age > ttlMs; negative ages and NaN were accepted. A future-dated, otherwise valid state could remain valid beyond its intended five-minute lifetime. This keeps the OAuth state TTL boundary explicit without changing the normal state flow.

Validation

  • bunx vitest run packages/server/src/services/oauth/state-manager.test.ts (3 passed)
  • bunx turbo typecheck --filter=@onequery/server --json (passed)
  • bunx oxfmt --check packages/server/src/services/oauth/state-manager.ts packages/server/src/services/oauth/state-manager.test.ts (passed)
  • git diff --check (passed)

Note: local oxlint panicked in its Rust allocator, so lint needs CI verification.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant