commit b2b0470a1d9267d042ec0ac66523c6635bf5b199
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 13:13:38 2026 +0200
chore: update .gitignore to include .vite-hooks and modify pnpm-lock.yaml for dependencies
commit d28fadb5cd8706c874e616102878b4a394ec84c1
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 13:08:04 2026 +0200
fix: remove timestamp conflict guard
commit c6998d9dbab19d09d3c8054feef1d2e4117555eb
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 12:11:51 2026 +0200
chore(release): v5.1.5
commit f33d168711804880e1f12e88d24290aae16cc258
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 11:58:35 2026 +0200
revert: compose.yml
commit d961e6535811a10c335525fb33a08d03e737278d
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 11:58:08 2026 +0200
refactor(agent): replace 'revert' terminology with 'restore' for clarity, resolves #3086
commit 17f351171be218e33f01c469d95e4164d4c8dc57
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 11:10:41 2026 +0200
refactor(pdf): simplify sidebar section filtering and update summary feature logic
commit d55179b9d76879e3204de185e8b53fadd0a107ed
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 09:53:37 2026 +0200
chore: update pnpm-lock.yaml and turbo.json
commit 7cade6980e1a04352536bd44ef773f338c4ef599
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 09:38:30 2026 +0200
fix(polyfill): add tested polyfill for Map Upsert methods
commit 26d175bb9c53d93225d1e907678445252c13d660
Merge: 1cf33dc6c 5b1297fa2
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 09:23:29 2026 +0200
Merge remote-tracking branch 'origin/main' into feat/explore-hono-orpc-migration
# Conflicts:
# packages/api/src/services/agent-url.ts
# packages/runtime-externals/package.json
commit 1cf33dc6c9d81735730ad656e16dab6501c6d6a1
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 09:22:12 2026 +0200
chore: preserve branch changes before main sync
commit b380a4b00fdbcdd81ff4f8ef72b330fd027ccda5
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Mon May 18 07:50:28 2026 +0200
chore: lot of fixes for monorepo migration
commit 8fcf0ec64e1c29572ebaff494338368bfcf75760
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 13:57:17 2026 +0200
chore: update knip version and refine web app routing with new SEO endpoints
commit 234e68086ff15610a93877354c98e2c020364533
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 12:10:06 2026 +0200
refactor(auth): update OAuth routes to include API prefix and remove unused schema endpoint
commit 91c84b9a8496b0ce21d71cae9f8b2a027638c9ac
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 11:54:29 2026 +0200
chore: update dependencies and enhance PWA metadata in web app
commit 150117d4a5a9dd6cd92c64891aad8cae90f6a7af
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 11:12:35 2026 +0200
docs: revise manifest-only pwa testing scope
commit 6b939a55661aec9dd8122b184e4b60a5c7325fb5
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 11:11:33 2026 +0200
docs: add manifest-only pwa design
commit 1422e1fc96c400948b273210a1067251087d15d4
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 11:05:04 2026 +0200
chore(dev): simplify server proxy config
commit bc2ff5a9f6fda41e6c40333c8f163aa23a6c5e48
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 11:04:50 2026 +0200
docs: add unsafe oauth redirect plan
commit 445359ebe9b96c1515bf1c4c3f73ba8a8448ec12
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 11:04:34 2026 +0200
feat(auth): add unsafe oauth redirect flag
commit 73fffdd24598e56b2793f7657919bc794835892e
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 10:55:02 2026 +0200
docs: design unsafe oauth redirect flag
commit c0066aa19c15fc8a4c8e5179ed49889c117519f4
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 10:22:04 2026 +0200
chore: update translation source paths
commit 9033da082418d252aafd6c2eed72f71f014be3d9
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 10:09:25 2026 +0200
refactor(arch): react spa + hono migration
commit 6f27936c11bda895977dc63ee550c3346d4ce24b
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 01:10:47 2026 +0200
docs: add docker nightly tagging design
commit ecc1fd9a88a0ee1dca2f1977dfc17f74527fe1da
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Thu May 14 20:05:44 2026 +0200
feat: migrate to hono spa server
4.4 KiB
Unsafe OAuth Redirect URI Flag Design
Date: 2026-05-15
Goal
Replace OAUTH_DYNAMIC_CLIENT_REDIRECT_HOSTS with a single explicit escape hatch:
FLAG_ALLOW_UNSAFE_OAUTH_REDIRECT_URI.
By default, dynamic OAuth client registration keeps the existing safe behavior: redirect URIs are allowed only when they target the app origin or local loopback callback hosts. When the flag is enabled, trusted self-hosted deployments may register any parseable redirect URI, including private network URLs, non-loopback http:// URLs, and custom schemes such as myapp://callback.
Non-Goals
- Do not change whether dynamic OAuth client registration is enabled.
- Do not change MCP OAuth audience handling, login, consent, token issuance, or public client registration defaults.
- Do not reuse
FLAG_ALLOW_UNSAFE_AI_BASE_URL; OAuth redirect handling is a separate trust boundary. - Do not keep a curated redirect-host allowlist after this change.
Architecture
The existing redirect URI policy remains centralized in @reactive-resume/utils/url-security.node.
Introduce a mode-based OAuth redirect validator API, for example:
isAllowedOAuthRedirectUri(input, trustedOrigins, { allowUnsafe })
Safe mode keeps the current rules:
- Reject malformed URIs.
- Reject embedded credentials.
- Reject URI fragments.
- Allow
http://localhost,http://127.0.0.1, andhttp://[::1]callbacks. - Allow
https://callbacks whose origin matchesAPP_URL. - Reject other public HTTPS hosts, private HTTPS hosts, non-loopback HTTP hosts, and non-HTTP schemes.
Unsafe mode deliberately weakens the redirect URI trust check:
- Allow any URI accepted by the platform URL parser.
- Allow custom schemes such as
myapp://callback. - Allow private and loopback hosts on any supported URL scheme.
- Allow non-loopback
http://URLs.
Unsafe mode should still reject strings that are not parseable as URLs. It does not preserve the current credentials or fragment restrictions, because the requested behavior is absolute unsafe: any parseable URI scheme is accepted.
Data Flow
packages/env/src/server.ts defines FLAG_ALLOW_UNSAFE_OAUTH_REDIRECT_URI as a z.stringbool().default(false) feature flag and removes OAUTH_DYNAMIC_CLIENT_REDIRECT_HOSTS.
packages/auth/src/config.ts uses the flag in the Better Auth hooks.before validation for /oauth2/register.
apps/server/src/http/auth.ts uses the same flag in the server-level registration preflight before forwarding the request to Better Auth.
Both validation paths must make the same allow or reject decision for the same redirect URI. The server preflight remains useful because it returns OAuth-shaped registration errors before the request enters Better Auth, while the Better Auth hook remains a defense-in-depth check.
Documentation
Remove OAUTH_DYNAMIC_CLIENT_REDIRECT_HOSTS from:
packages/env/src/server.tsturbo.json.env.example- Docker and self-hosting docs
- Quickstart docs
Add FLAG_ALLOW_UNSAFE_OAUTH_REDIRECT_URI to the feature flag sections and env examples with a warning that it is only appropriate for trusted self-hosted deployments. The warning should call out that enabling it permits arbitrary OAuth redirect URIs and can enable phishing or token exfiltration if used on public or multi-tenant instances.
Error Handling
Rejected safe-mode redirects continue to return the existing error shape:
- Better Auth hook:
BAD_REQUESTwithredirect_uri is not allowed for dynamic client registration. - Server preflight:
400withinvalid_redirect_uri.
Unsafe mode only returns those errors when the redirect URI cannot be parsed as a URL or a non-string entry is supplied in redirect_uris.
Testing
Update focused tests in the relevant packages:
- URL policy tests cover safe mode preserving current allowed and rejected cases.
- URL policy tests cover unsafe mode allowing custom schemes, private hosts, non-loopback
http://, credentials, and fragments when the URI is parseable. - Auth/server tests cover the env mock shape after removing
OAUTH_DYNAMIC_CLIENT_REDIRECT_HOSTS. - Documentation and env references no longer mention the removed variable.
Run focused validation after implementation:
pnpm --filter @reactive-resume/utils test -- src/url-security.node.test.ts
pnpm --filter server test -- src/http/auth.test.ts
pnpm --filter @reactive-resume/auth typecheck
pnpm --filter server typecheck
pnpm exec turbo boundaries