QA-source: #21845 · identity-auth.linked-accounts-social · acceptance[3]
Clause A4 (and N4) of identity-auth.linked-accounts-social (rev 2) fail in the follow-up run #21845 (subject 316be321e); an independent verifier (RUNNER rule 7) confirmed it from source and live: medium, predates 17.6.0.
Reproduction
- Stock showcase boot;
/api/v1/auth/config reports socialProviders [].
- Sign in; Account → Linked Accounts → "Link Social Account"; choose Google; Confirm.
- Expected: on a provider-less boot the action is absent (or names the missing provider); on a configured boot it links the chosen provider to the signed-in user.
- Actual: a fixed list of 7 providers; the browser navigates to
GET /api/v1/auth/sign-in/social?provider=google → 404. With a configured OIDC provider the action still cannot link (it offers only the static list, and targets the sign-in door).
Mechanism
packages/platform-objects/src/identity/sys-account.object.ts:58-84 declares link_social as a type:'url' action to the sign-in route with a static option list and no visibility gate. better-auth serves sign-in/social and link-social as POST only (route ledger auth-route-ledger.ts :159, :167); linking needs the authenticated POST /api/v1/auth/link-social, which answers a URL to navigate to.
Done when
The action POSTs the link door and then navigates to the returned URL, its options come from the configured providers, and it is hidden when none is configured; a dogfood test links through it.
Generated by Claude Code
QA-source: #21845 · identity-auth.linked-accounts-social · acceptance[3]
Clause A4 (and N4) of
identity-auth.linked-accounts-social(rev 2) fail in the follow-up run #21845 (subject316be321e); an independent verifier (RUNNER rule 7) confirmed it from source and live: medium, predates 17.6.0.Reproduction
/api/v1/auth/configreportssocialProviders [].GET /api/v1/auth/sign-in/social?provider=google→ 404. With a configured OIDC provider the action still cannot link (it offers only the static list, and targets the sign-in door).Mechanism
packages/platform-objects/src/identity/sys-account.object.ts:58-84declareslink_socialas atype:'url'action to the sign-in route with a static option list and no visibility gate. better-auth servessign-in/socialandlink-socialas POST only (route ledgerauth-route-ledger.ts:159, :167); linking needs the authenticatedPOST /api/v1/auth/link-social, which answers a URL to navigate to.Done when
The action POSTs the link door and then navigates to the returned URL, its options come from the configured providers, and it is hidden when none is configured; a dogfood test links through it.
Generated by Claude Code