feat(auth): 需要 step-up 的第三方账号显式绑定流程 - #81
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What & why
实现 #64 / 矩阵 D-7:PR #62 之后管理员被禁止自动关联第三方身份,但「显式已认证绑定流程」一直缺失——管理员永远无法用 Google/GitHub 登录。本 PR 补上该流程:
POST /auth/oauth/{provider}/bind/start(auth 域):当前会话 + step-up 重新输密码(verify_password复用)通过后,绑定意图(user_id/provider/10 分钟 TTL)写入服务端 session(与 authlib OAuth state 同生命周期),返回 provider 授权 URL;oauth_callback识别有效绑定意图后走_handle_bind_callback——校验「发起绑定的会话本人」(cookie 会话 user_id 必须与意图一致)、未验证邮箱拒绝(fix(auth): harden OAuth linking and admin seed against account takeover #62 语义一致)、成功落user_oauth_account并以#provider=xx&bind=linked回跳(不建新登录会话,保持当前会话);link_oauth_identity_to_user:两类冲突显式抛OAuthBindConflictError(目标账号已有同 provider 绑定→先解绑、身份已被其它账号绑定→拒绝),防置换攻击;Refs #64。Closes #64。
Area
Verification
tests_oauth_patch/test_oauth_bind.py六场景:正常绑定(link 落库、不建会话、fragment 无凭证)/ 密码错误 401 / 已有绑定冲突回跳 / 未验证邮箱拒绝 / 发起人与会话不一致拒绝 / 无意图回退登录分支tests_oauth_patch/全套 35 项绿(含 [P2][Security] OAuth 回调经 URL Fragment 向前端传递完整登录凭证 #63 转正断言)make test-backend(TEST_PG_PORT=5436)exit 0Verifier verdict
CI 门禁即机器 Verifier;四验收场景 + 会话不匹配由独立 mock 回归钉死。
Checklist
issue-<number>-<short-slug>and PR links the issueNotes for reviewer
设置页的绑定发起 UI 属前端后续(端点契约已定:
{password}→{authorize_url},成功回跳#bind=linked);解绑端点未包含在本切片。真实 provider E2E 与 #63 同样留待有真实 OAuth 应用环境时人工回归。