Skip to content

security(auth): implicit account linking on social / OIDC sign-in is broader than the platform's account-ownership rules allow — detail withheld pending maintainer #21846

Description

@objectstack-fleet

QA-source: #21845 · identity-auth.linked-accounts-social · outside the item's clauses

Found while building the OIDC fixture for identity-auth.linked-accounts-social in the follow-up run #21845 (subject 316be321e); confirmed by an independent verifier (RUNNER rule 7) for every condition.

  • Class: authorization (account ownership across an external identity provider). Under RUNNER rule 2 the reproduction and the mechanism are withheld pending maintainer; they are held in the PM session (Claude Code session session_018zT8d8NpiQ1ExhuNd5TxY6).
  • Ruled: this is a defect, to be tightened. The platform's own cloud identity provider keeps its documented exception; every other provider must meet the library's standard local-ownership requirement before an identity is linked implicitly, and a user's unlink must stop the provider from re-linking implicitly. Recorded by the PM seat from the maintainer's answer in that session, 2026-10-05, choosing 「算漏洞,收紧」.
  • Severity as judged by the verifier: high where self-registration is open; otherwise lower. Predates 17.6.0.
  • Owning repo: objectstack. No open card covers it.

Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:identityLogin and identity — sign-up, sessions, organization membership, SSObugSomething isn't workingdomain:servicespriority:p1High: required for production / M2security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions