QA-source: #21845 · identity-auth.linked-accounts-social · outside the item's clauses
Found while building the OIDC fixture for identity-auth.linked-accounts-social in the follow-up run #21845 (subject 316be321e); confirmed by an independent verifier (RUNNER rule 7) for every condition.
- Class: authorization (account ownership across an external identity provider). Under RUNNER rule 2 the reproduction and the mechanism are withheld pending maintainer; they are held in the PM session (Claude Code session
session_018zT8d8NpiQ1ExhuNd5TxY6).
- Ruled: this is a defect, to be tightened. The platform's own cloud identity provider keeps its documented exception; every other provider must meet the library's standard local-ownership requirement before an identity is linked implicitly, and a user's unlink must stop the provider from re-linking implicitly. Recorded by the PM seat from the maintainer's answer in that session, 2026-10-05, choosing 「算漏洞,收紧」.
- Severity as judged by the verifier: high where self-registration is open; otherwise lower. Predates 17.6.0.
- Owning repo:
objectstack. No open card covers it.
Generated by Claude Code
QA-source: #21845 · identity-auth.linked-accounts-social · outside the item's clauses
Found while building the OIDC fixture for
identity-auth.linked-accounts-socialin the follow-up run #21845 (subject316be321e); confirmed by an independent verifier (RUNNER rule 7) for every condition.session_018zT8d8NpiQ1ExhuNd5TxY6).objectstack. No open card covers it.Generated by Claude Code