Repository navigation
docs(sso): the OIDC flow uses /sign-in/social and /callback/:id - #21926
Merged
Merged
Conversation
The OAuth flow section told readers to call POST /api/v1/auth/sign-in/oauth2, a route nothing registers. better-auth's generic-OAuth plugin, which carries the oidcProviders entries, adds no endpoints: it registers each entry as a social provider, so sign-in starts at /sign-in/social with the entry's providerId as `provider` and returns through /callback/:id. Claude-Session: https://claude.ai/code/session_01VDtqoecgES7ScQYGbFVDRv Co-authored-by: Claude <noreply@anthropic.com>
Contributor
Author
Contract reviewServed-tier: ① Changesets — TRUE
② Review faces — TRUE
③ Scope — TRUE
Implemented-by: VERDICT: PASS Generated by Claude Code |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #21885
Clause-②: no
What changes
content/docs/permissions/sso.mdx, the "OAuth flow" section only. Step 2 of the OIDC flow told readers to callPOST /api/v1/auth/sign-in/oauth2with{ providerId }. Nothing registers that route, so a reader following the page got a 404. The OIDC steps now use the two routes the social flow already uses:POST /api/v1/auth/sign-in/socialwith{ provider: "okta", callbackURL }, whereprovideris theoidcProvidersentry'sproviderId./api/v1/auth/callback/okta. better-auth exchanges the code, reads the profile from the ID token oruserInfoUrl, creates a session and redirects tocallbackURL.oidcProvidersentry as a social provider and adds no endpoints of its own.No product change, no other page, no changeset (docs do not publish).
Grounding for each route
POST /api/v1/auth/sign-in/social(OIDC step 2, changed; social step 2, re-checked and unchanged)packages/plugins/plugin-auth/src/auth-route-ledger.tsline 167:{ route: 'POST /api/v1/auth/sign-in/social', family: 'core-auth', source: 'better-auth', disposition: 'sdk', client: 'auth.signInWithProvider' },'POST /api/v1/auth/sign-in/social',dist/api/routes/sign-in.mjsline 40:provider: SocialProviderListEnum. In@better-auth/coredist/social-providers/index.mjsline 78 that isz.enum(socialProviderList).or(z.string()), so a generic provider id is accepted. The handler looksc.body.providerup inc.context.socialProviders.dist/plugins/generic-oauth/index.mjslines 61-66: "registers any OAuth/OIDC provider as a first-class social provider. Providers are used through the standardsignIn.socialandcallback/:idcore endpoints — no plugin-specific endpoints needed." Itsinitprepends the generic providers toctx.socialProviders(line 272).packages/plugins/plugin-auth/src/implicit-account-linking.test.ts:/sign-in/social→/callback/:id) through generic-OAuth providers"{ provider: providerId, callbackURL: AFTER, disableRedirect: true, ...extraBody },posted tosign-in/social/api/v1/auth/callback/:id(OIDC step 4, now named; social step 4/callback/google, re-checked and unchanged)auth-route-ledger.tsline 321'GET /api/v1/auth/callback/:id',and line 372'POST /api/v1/auth/callback/:id',dist/oauth2/utils.mjsline 29:if (!provider.callbackPath) returnthe path/callback/plusprovider.id. The generic-OAuth plugin sets nocallbackPath, andauth-manager.tspassesproviderId: p.providerIdstraight through (line 3710).implicit-account-linking.test.tsline 254: the callback is requested at${BASE}/api/v1/auth/callback/${providerId}?code=code-1&state=….POST /api/v1/auth/sign-in/oauth2(removed)grep -c "sign-in/oauth2" packages/plugins/plugin-auth/src/auth-route-ledger.tsgives0, in both the ledger rows and the published-route list.The section names no other route.
Validation
All at head
57258e13b4.node scripts/pm/dispatch-gates.mjsderived 44 gate commands for this one-file change. Every one of them exited 0, and--ranreconciled them: "44 derived famil(ies) accounted for — 44 run, 0 NOT-MEASURED (a DERIVED zero — all 44 recorded an exit code and none of them is 3)".check:doc-authoring,check:doc-anchors(429 fragment links resolve),check-doc-route-spelling --advisory("every shape-matched literal spells its ledger row"),check:docs-single-h1,check:doc-frontmatter,check:docs-redirects,check:docs-transcript-drift,check:nul-bytes. All passed.check:doc-formula-expressions,check:doc-security-posture,check:docs-transcript-driftandcheck:skill-examples. I built@objectstack/lint...,@objectstack/specand@objectstack/client-react..., then re-ran all four. Each exited 0.Acceptance notes
POST /api/v1/auth/sign-in/sso. The ledger's pinned config (LEDGERED_PLUGIN_CONFIG) does not turn onsso, so the ledger neither confirms nor refutes that route. Noting it here only.Changes 1 file:
content/docs/permissions/sso.mdx, +8 / -3.Generated by Claude Code