Files
Reactive-Resume/docs/superpowers/specs/2026-05-15-unsafe-oauth-redirect-uri-design.md
T
Amruth Pillai 62f8270b3e Squashed commit of the following:
commit b2b0470a1d9267d042ec0ac66523c6635bf5b199
Author: Amruth Pillai <im.amruth@gmail.com>
Date:   Tue May 19 13:13:38 2026 +0200

    chore: update .gitignore to include .vite-hooks and modify pnpm-lock.yaml for dependencies

commit d28fadb5cd8706c874e616102878b4a394ec84c1
Author: Amruth Pillai <im.amruth@gmail.com>
Date:   Tue May 19 13:08:04 2026 +0200

    fix: remove timestamp conflict guard

commit c6998d9dbab19d09d3c8054feef1d2e4117555eb
Author: Amruth Pillai <im.amruth@gmail.com>
Date:   Tue May 19 12:11:51 2026 +0200

    chore(release): v5.1.5

commit f33d168711804880e1f12e88d24290aae16cc258
Author: Amruth Pillai <im.amruth@gmail.com>
Date:   Tue May 19 11:58:35 2026 +0200

    revert: compose.yml

commit d961e6535811a10c335525fb33a08d03e737278d
Author: Amruth Pillai <im.amruth@gmail.com>
Date:   Tue May 19 11:58:08 2026 +0200

    refactor(agent): replace 'revert' terminology with 'restore' for clarity, resolves #3086

commit 17f351171be218e33f01c469d95e4164d4c8dc57
Author: Amruth Pillai <im.amruth@gmail.com>
Date:   Tue May 19 11:10:41 2026 +0200

    refactor(pdf): simplify sidebar section filtering and update summary feature logic

commit d55179b9d76879e3204de185e8b53fadd0a107ed
Author: Amruth Pillai <im.amruth@gmail.com>
Date:   Tue May 19 09:53:37 2026 +0200

    chore: update pnpm-lock.yaml and turbo.json

commit 7cade6980e1a04352536bd44ef773f338c4ef599
Author: Amruth Pillai <im.amruth@gmail.com>
Date:   Tue May 19 09:38:30 2026 +0200

    fix(polyfill): add tested polyfill for Map Upsert methods

commit 26d175bb9c53d93225d1e907678445252c13d660
Merge: 1cf33dc6c 5b1297fa2
Author: Amruth Pillai <im.amruth@gmail.com>
Date:   Tue May 19 09:23:29 2026 +0200

    Merge remote-tracking branch 'origin/main' into feat/explore-hono-orpc-migration

    # Conflicts:
    #	packages/api/src/services/agent-url.ts
    #	packages/runtime-externals/package.json

commit 1cf33dc6c9d81735730ad656e16dab6501c6d6a1
Author: Amruth Pillai <im.amruth@gmail.com>
Date:   Tue May 19 09:22:12 2026 +0200

    chore: preserve branch changes before main sync

commit b380a4b00fdbcdd81ff4f8ef72b330fd027ccda5
Author: Amruth Pillai <im.amruth@gmail.com>
Date:   Mon May 18 07:50:28 2026 +0200

    chore: lot of fixes for monorepo migration

commit 8fcf0ec64e1c29572ebaff494338368bfcf75760
Author: Amruth Pillai <im.amruth@gmail.com>
Date:   Fri May 15 13:57:17 2026 +0200

    chore: update knip version and refine web app routing with new SEO endpoints

commit 234e68086ff15610a93877354c98e2c020364533
Author: Amruth Pillai <im.amruth@gmail.com>
Date:   Fri May 15 12:10:06 2026 +0200

    refactor(auth): update OAuth routes to include API prefix and remove unused schema endpoint

commit 91c84b9a8496b0ce21d71cae9f8b2a027638c9ac
Author: Amruth Pillai <im.amruth@gmail.com>
Date:   Fri May 15 11:54:29 2026 +0200

    chore: update dependencies and enhance PWA metadata in web app

commit 150117d4a5a9dd6cd92c64891aad8cae90f6a7af
Author: Amruth Pillai <im.amruth@gmail.com>
Date:   Fri May 15 11:12:35 2026 +0200

    docs: revise manifest-only pwa testing scope

commit 6b939a55661aec9dd8122b184e4b60a5c7325fb5
Author: Amruth Pillai <im.amruth@gmail.com>
Date:   Fri May 15 11:11:33 2026 +0200

    docs: add manifest-only pwa design

commit 1422e1fc96c400948b273210a1067251087d15d4
Author: Amruth Pillai <im.amruth@gmail.com>
Date:   Fri May 15 11:05:04 2026 +0200

    chore(dev): simplify server proxy config

commit bc2ff5a9f6fda41e6c40333c8f163aa23a6c5e48
Author: Amruth Pillai <im.amruth@gmail.com>
Date:   Fri May 15 11:04:50 2026 +0200

    docs: add unsafe oauth redirect plan

commit 445359ebe9b96c1515bf1c4c3f73ba8a8448ec12
Author: Amruth Pillai <im.amruth@gmail.com>
Date:   Fri May 15 11:04:34 2026 +0200

    feat(auth): add unsafe oauth redirect flag

commit 73fffdd24598e56b2793f7657919bc794835892e
Author: Amruth Pillai <im.amruth@gmail.com>
Date:   Fri May 15 10:55:02 2026 +0200

    docs: design unsafe oauth redirect flag

commit c0066aa19c15fc8a4c8e5179ed49889c117519f4
Author: Amruth Pillai <im.amruth@gmail.com>
Date:   Fri May 15 10:22:04 2026 +0200

    chore: update translation source paths

commit 9033da082418d252aafd6c2eed72f71f014be3d9
Author: Amruth Pillai <im.amruth@gmail.com>
Date:   Fri May 15 10:09:25 2026 +0200

    refactor(arch): react spa + hono migration

commit 6f27936c11bda895977dc63ee550c3346d4ce24b
Author: Amruth Pillai <im.amruth@gmail.com>
Date:   Fri May 15 01:10:47 2026 +0200

    docs: add docker nightly tagging design

commit ecc1fd9a88a0ee1dca2f1977dfc17f74527fe1da
Author: Amruth Pillai <im.amruth@gmail.com>
Date:   Thu May 14 20:05:44 2026 +0200

    feat: migrate to hono spa server
2026-05-19 13:14:21 +02:00

4.4 KiB

Unsafe OAuth Redirect URI Flag Design

Date: 2026-05-15

Goal

Replace OAUTH_DYNAMIC_CLIENT_REDIRECT_HOSTS with a single explicit escape hatch: FLAG_ALLOW_UNSAFE_OAUTH_REDIRECT_URI.

By default, dynamic OAuth client registration keeps the existing safe behavior: redirect URIs are allowed only when they target the app origin or local loopback callback hosts. When the flag is enabled, trusted self-hosted deployments may register any parseable redirect URI, including private network URLs, non-loopback http:// URLs, and custom schemes such as myapp://callback.

Non-Goals

  • Do not change whether dynamic OAuth client registration is enabled.
  • Do not change MCP OAuth audience handling, login, consent, token issuance, or public client registration defaults.
  • Do not reuse FLAG_ALLOW_UNSAFE_AI_BASE_URL; OAuth redirect handling is a separate trust boundary.
  • Do not keep a curated redirect-host allowlist after this change.

Architecture

The existing redirect URI policy remains centralized in @reactive-resume/utils/url-security.node.

Introduce a mode-based OAuth redirect validator API, for example:

isAllowedOAuthRedirectUri(input, trustedOrigins, { allowUnsafe })

Safe mode keeps the current rules:

  • Reject malformed URIs.
  • Reject embedded credentials.
  • Reject URI fragments.
  • Allow http://localhost, http://127.0.0.1, and http://[::1] callbacks.
  • Allow https:// callbacks whose origin matches APP_URL.
  • Reject other public HTTPS hosts, private HTTPS hosts, non-loopback HTTP hosts, and non-HTTP schemes.

Unsafe mode deliberately weakens the redirect URI trust check:

  • Allow any URI accepted by the platform URL parser.
  • Allow custom schemes such as myapp://callback.
  • Allow private and loopback hosts on any supported URL scheme.
  • Allow non-loopback http:// URLs.

Unsafe mode should still reject strings that are not parseable as URLs. It does not preserve the current credentials or fragment restrictions, because the requested behavior is absolute unsafe: any parseable URI scheme is accepted.

Data Flow

packages/env/src/server.ts defines FLAG_ALLOW_UNSAFE_OAUTH_REDIRECT_URI as a z.stringbool().default(false) feature flag and removes OAUTH_DYNAMIC_CLIENT_REDIRECT_HOSTS.

packages/auth/src/config.ts uses the flag in the Better Auth hooks.before validation for /oauth2/register.

apps/server/src/http/auth.ts uses the same flag in the server-level registration preflight before forwarding the request to Better Auth.

Both validation paths must make the same allow or reject decision for the same redirect URI. The server preflight remains useful because it returns OAuth-shaped registration errors before the request enters Better Auth, while the Better Auth hook remains a defense-in-depth check.

Documentation

Remove OAUTH_DYNAMIC_CLIENT_REDIRECT_HOSTS from:

  • packages/env/src/server.ts
  • turbo.json
  • .env.example
  • Docker and self-hosting docs
  • Quickstart docs

Add FLAG_ALLOW_UNSAFE_OAUTH_REDIRECT_URI to the feature flag sections and env examples with a warning that it is only appropriate for trusted self-hosted deployments. The warning should call out that enabling it permits arbitrary OAuth redirect URIs and can enable phishing or token exfiltration if used on public or multi-tenant instances.

Error Handling

Rejected safe-mode redirects continue to return the existing error shape:

  • Better Auth hook: BAD_REQUEST with redirect_uri is not allowed for dynamic client registration.
  • Server preflight: 400 with invalid_redirect_uri.

Unsafe mode only returns those errors when the redirect URI cannot be parsed as a URL or a non-string entry is supplied in redirect_uris.

Testing

Update focused tests in the relevant packages:

  • URL policy tests cover safe mode preserving current allowed and rejected cases.
  • URL policy tests cover unsafe mode allowing custom schemes, private hosts, non-loopback http://, credentials, and fragments when the URI is parseable.
  • Auth/server tests cover the env mock shape after removing OAUTH_DYNAMIC_CLIENT_REDIRECT_HOSTS.
  • Documentation and env references no longer mention the removed variable.

Run focused validation after implementation:

pnpm --filter @reactive-resume/utils test -- src/url-security.node.test.ts
pnpm --filter server test -- src/http/auth.test.ts
pnpm --filter @reactive-resume/auth typecheck
pnpm --filter server typecheck
pnpm exec turbo boundaries