commit b2b0470a1d9267d042ec0ac66523c6635bf5b199
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 13:13:38 2026 +0200
chore: update .gitignore to include .vite-hooks and modify pnpm-lock.yaml for dependencies
commit d28fadb5cd8706c874e616102878b4a394ec84c1
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 13:08:04 2026 +0200
fix: remove timestamp conflict guard
commit c6998d9dbab19d09d3c8054feef1d2e4117555eb
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 12:11:51 2026 +0200
chore(release): v5.1.5
commit f33d168711804880e1f12e88d24290aae16cc258
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 11:58:35 2026 +0200
revert: compose.yml
commit d961e6535811a10c335525fb33a08d03e737278d
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 11:58:08 2026 +0200
refactor(agent): replace 'revert' terminology with 'restore' for clarity, resolves #3086
commit 17f351171be218e33f01c469d95e4164d4c8dc57
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 11:10:41 2026 +0200
refactor(pdf): simplify sidebar section filtering and update summary feature logic
commit d55179b9d76879e3204de185e8b53fadd0a107ed
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 09:53:37 2026 +0200
chore: update pnpm-lock.yaml and turbo.json
commit 7cade6980e1a04352536bd44ef773f338c4ef599
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 09:38:30 2026 +0200
fix(polyfill): add tested polyfill for Map Upsert methods
commit 26d175bb9c53d93225d1e907678445252c13d660
Merge: 1cf33dc6c 5b1297fa2
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 09:23:29 2026 +0200
Merge remote-tracking branch 'origin/main' into feat/explore-hono-orpc-migration
# Conflicts:
# packages/api/src/services/agent-url.ts
# packages/runtime-externals/package.json
commit 1cf33dc6c9d81735730ad656e16dab6501c6d6a1
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 09:22:12 2026 +0200
chore: preserve branch changes before main sync
commit b380a4b00fdbcdd81ff4f8ef72b330fd027ccda5
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Mon May 18 07:50:28 2026 +0200
chore: lot of fixes for monorepo migration
commit 8fcf0ec64e1c29572ebaff494338368bfcf75760
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 13:57:17 2026 +0200
chore: update knip version and refine web app routing with new SEO endpoints
commit 234e68086ff15610a93877354c98e2c020364533
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 12:10:06 2026 +0200
refactor(auth): update OAuth routes to include API prefix and remove unused schema endpoint
commit 91c84b9a8496b0ce21d71cae9f8b2a027638c9ac
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 11:54:29 2026 +0200
chore: update dependencies and enhance PWA metadata in web app
commit 150117d4a5a9dd6cd92c64891aad8cae90f6a7af
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 11:12:35 2026 +0200
docs: revise manifest-only pwa testing scope
commit 6b939a55661aec9dd8122b184e4b60a5c7325fb5
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 11:11:33 2026 +0200
docs: add manifest-only pwa design
commit 1422e1fc96c400948b273210a1067251087d15d4
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 11:05:04 2026 +0200
chore(dev): simplify server proxy config
commit bc2ff5a9f6fda41e6c40333c8f163aa23a6c5e48
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 11:04:50 2026 +0200
docs: add unsafe oauth redirect plan
commit 445359ebe9b96c1515bf1c4c3f73ba8a8448ec12
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 11:04:34 2026 +0200
feat(auth): add unsafe oauth redirect flag
commit 73fffdd24598e56b2793f7657919bc794835892e
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 10:55:02 2026 +0200
docs: design unsafe oauth redirect flag
commit c0066aa19c15fc8a4c8e5179ed49889c117519f4
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 10:22:04 2026 +0200
chore: update translation source paths
commit 9033da082418d252aafd6c2eed72f71f014be3d9
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 10:09:25 2026 +0200
refactor(arch): react spa + hono migration
commit 6f27936c11bda895977dc63ee550c3346d4ce24b
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 01:10:47 2026 +0200
docs: add docker nightly tagging design
commit ecc1fd9a88a0ee1dca2f1977dfc17f74527fe1da
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Thu May 14 20:05:44 2026 +0200
feat: migrate to hono spa server
7.3 KiB
Unsafe OAuth Redirect URI Flag Implementation Plan
For agentic workers: REQUIRED SUB-SKILL: Use superpowers:subagent-driven-development (recommended) or superpowers:executing-plans to implement this plan task-by-task. Steps use checkbox (
- [ ]) syntax for tracking.
Goal: Replace OAUTH_DYNAMIC_CLIENT_REDIRECT_HOSTS with FLAG_ALLOW_UNSAFE_OAUTH_REDIRECT_URI, preserving safe defaults and allowing any parseable redirect URI only when the flag is enabled.
Architecture: Keep OAuth redirect URI policy centralized in packages/utils/src/url-security.node.ts. Pass the new env flag from both Better Auth hook validation and the server auth preflight so both paths make identical decisions. Update env/docs references and tests in the same slice.
Tech Stack: TypeScript, Zod env schema, Better Auth hook middleware, Vitest, Turborepo env filtering, MDX docs.
File Structure
- Modify
packages/utils/src/url-security.node.ts: Change the OAuth redirect validator from allowlist-based to mode-based. - Modify
packages/utils/src/url-security.node.test.ts: Update safe-mode tests and add unsafe-mode coverage. - Modify
packages/env/src/server.ts: Remove the old allowlist env var and addFLAG_ALLOW_UNSAFE_OAUTH_REDIRECT_URI. - Modify
packages/auth/src/config.ts: Remove host-list parsing and pass{ allowUnsafe: env.FLAG_ALLOW_UNSAFE_OAUTH_REDIRECT_URI }. - Modify
apps/server/src/http/auth.ts: Remove host-list parsing and pass the same flag to the validator. - Modify
apps/server/src/http/auth.test.ts: Update env mock shape and preserve existing local edits. - Modify
turbo.json,.env.example, and MDX docs: Replace old env references with the new flag and warnings.
Task 1: URL Policy Tests And Validator
Files:
-
Modify:
packages/utils/src/url-security.node.test.ts -
Modify:
packages/utils/src/url-security.node.ts -
Step 1: Write the failing safe/unsafe OAuth redirect tests
Use this shape in packages/utils/src/url-security.node.test.ts:
describe("isAllowedOAuthRedirectUri", () => {
const trustedOrigins = ["https://app.example.com"];
it("returns false for malformed URI", () => {
expect(isAllowedOAuthRedirectUri("nope", trustedOrigins)).toBe(false);
});
it("returns true for any parseable URI when unsafe mode is enabled", () => {
const options = { allowUnsafe: true };
expect(isAllowedOAuthRedirectUri("myapp://callback", trustedOrigins, options)).toBe(true);
expect(isAllowedOAuthRedirectUri("http://example.com/cb", trustedOrigins, options)).toBe(true);
expect(isAllowedOAuthRedirectUri("https://192.168.1.1/cb", trustedOrigins, options)).toBe(true);
expect(isAllowedOAuthRedirectUri("https://u:p@app.example.com/cb#x", trustedOrigins, options)).toBe(true);
expect(isAllowedOAuthRedirectUri("not a url", trustedOrigins, options)).toBe(false);
});
});
- Step 2: Run the focused utils test and verify it fails
Run: pnpm --filter @reactive-resume/utils test -- src/url-security.node.test.ts
Expected before implementation: TypeScript/test failure because isAllowedOAuthRedirectUri still requires the removed allowlist argument.
- Step 3: Implement mode-based OAuth redirect validation
Use this signature in packages/utils/src/url-security.node.ts:
type OAuthRedirectUriOptions = {
allowUnsafe?: boolean;
};
export function isAllowedOAuthRedirectUri(
input: string,
trustedOrigins: string[],
options?: OAuthRedirectUriOptions,
) {
const parsed = parseUrl(input);
if (!parsed) return false;
if (options?.allowUnsafe) return true;
if (parsed.username || parsed.password) return false;
if (parsed.hash) return false;
const origin = parsed.origin.toLowerCase();
const hostname = normalizeHostname(parsed.hostname);
if (parsed.protocol === "http:") return isOAuthLoopbackRedirectHost(hostname);
if (parsed.protocol !== "https:") return false;
if (isPrivateOrLoopbackHost(hostname)) return false;
return trustedOrigins.includes(origin);
}
- Step 4: Run the focused utils test and verify it passes
Run: pnpm --filter @reactive-resume/utils test -- src/url-security.node.test.ts
Expected after implementation: all tests in url-security.node.test.ts pass.
Task 2: Env And Runtime Wiring
Files:
-
Modify:
packages/env/src/server.ts -
Modify:
packages/auth/src/config.ts -
Modify:
apps/server/src/http/auth.ts -
Modify:
apps/server/src/http/auth.test.ts -
Modify:
turbo.json -
Step 1: Update env schema and Turbo env list
In packages/env/src/server.ts, remove:
OAUTH_DYNAMIC_CLIENT_REDIRECT_HOSTS: z.string().optional(),
Add with feature flags:
FLAG_ALLOW_UNSAFE_OAUTH_REDIRECT_URI: z.stringbool().default(false),
In turbo.json, remove "OAUTH_DYNAMIC_CLIENT_REDIRECT_HOSTS" and add "FLAG_ALLOW_UNSAFE_OAUTH_REDIRECT_URI" beside the other flags.
- Step 2: Wire the flag into Better Auth config
In packages/auth/src/config.ts, remove parseAllowedHostList usage and call:
if (
!isAllowedOAuthRedirectUri(uri, TRUSTED_ORIGINS, {
allowUnsafe: env.FLAG_ALLOW_UNSAFE_OAUTH_REDIRECT_URI,
})
) {
throw new APIError("BAD_REQUEST", {
message: "redirect_uri is not allowed for dynamic client registration",
});
}
- Step 3: Wire the flag into server preflight
In apps/server/src/http/auth.ts, remove parseAllowedHostList usage and call:
!isAllowedOAuthRedirectUri(redirectUri, oauthTrustedOrigins, {
allowUnsafe: env.FLAG_ALLOW_UNSAFE_OAUTH_REDIRECT_URI,
})
Update the test env mock in apps/server/src/http/auth.test.ts:
env: {
SERVER_PORT: 3001,
APP_URL: "http://localhost:3000",
FLAG_ALLOW_UNSAFE_OAUTH_REDIRECT_URI: false,
},
- Step 4: Run focused typechecks
Run:
pnpm --filter @reactive-resume/auth typecheck
pnpm --filter server typecheck
Expected: both commands exit 0.
Task 3: Docs And Env Examples
Files:
-
Modify:
.env.example -
Modify:
docs/self-hosting/docker.mdx -
Modify:
docs/self-hosting/sso.mdx -
Modify:
docs/getting-started/quickstart.mdx -
Step 1: Replace old env docs with the new flag
Remove all OAUTH_DYNAMIC_CLIENT_REDIRECT_HOSTS references.
Add this warning wherever feature flags are documented:
`FLAG_ALLOW_UNSAFE_OAUTH_REDIRECT_URI`: Allows dynamic OAuth client registration to use any parseable redirect URI, including custom schemes, private hosts, and non-loopback `http://` URLs. Keep disabled unless this is a trusted self-hosted deployment. Enabling it on public or multi-tenant instances can enable phishing or token exfiltration.
- Step 2: Verify the removed env is gone from product code and docs
Run: rg -n "OAUTH_DYNAMIC_CLIENT_REDIRECT_HOSTS" . --glob "!docs/superpowers/**"
Expected: no matches outside the approved design and implementation plan documents.
Run: rg -n "FLAG_ALLOW_UNSAFE_OAUTH_REDIRECT_URI" .
Expected: matches in env schema, Turbo config, docs, tests, and runtime validation paths.
Task 4: Final Verification
Files:
-
Verify all modified files.
-
Step 1: Run focused tests
Run:
pnpm --filter @reactive-resume/utils test -- src/url-security.node.test.ts
pnpm --filter server test -- src/http/auth.test.ts
Expected: both commands exit 0.
- Step 2: Run focused typechecks and boundaries
Run:
pnpm --filter @reactive-resume/auth typecheck
pnpm --filter server typecheck
pnpm exec turbo boundaries
Expected: all commands exit 0.