fix(auth): resolve BankID confirmation and email-hook link hosts through the trusted-origin registry (#2380)
* fix(auth): resolve BankID confirmation and email-hook link hosts through the trusted-origin registry The BankID confirmation mail built its /auth/callback link from the raw forwarded host and protocol; it is the one auth link GoTrue's redirect allowlist never sees, since the link is minted here and sent through Resend. The Send Email hook followed GoTrue's redirect_to verbatim: the webhook signature proves who sent the payload, not that every destination in it should be followed, and the GoTrue allowlist is a hand-configured glob. Both now resolve the destination through lib/domains/trusted-app-origin like every other auth link (canonical, this deployment's own Vercel hosts, or a registered brands.domain). Unknown, lookalike, credential-bearing, non-default-port and malformed destinations collapse to the canonical /auth/callback with no next path; a registered brand host over http is upgraded to https. Brand sender identity is taken from the RESOLVED host, so mail branding and link destination always agree. A brands-table read failure refuses instead of mailing a wrong-host link: the BankID helper returns step resolve_origin (signup rolls back, login re-send logs), the hook answers 500 so Supabase retries. Drops the proto parameter from the BankID helper; the resolver owns the scheme. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0189cGB2YxptqVxBLJ2RkB5T * fix(auth): read the sender brand once, failure-aware, before minting or sending auth mail CodeRabbit: resolveTrustedAppOrigin could classify a brand host, then the separate resolveBrandByHost read for the sender could fail and return null, so a brand link went out with the platform sender; the BankID helper had already minted the magic link by then. Both sites now read the brand with resolveBrandResultByHost on the resolved host and refuse on a failed read for any non-canonical origin (BankID: step resolve_origin before generateLink; hook: 500 so Supabase retries). On the canonical origin a failed read is the platform sender either way, so mail still goes out. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0189cGB2YxptqVxBLJ2RkB5T * fix(auth): treat a credential-bearing redirect_to as untrusted in the email hook Superagent P2: URL.origin drops userinfo, so a redirect_to with credentials on a served host passed the origin comparison and was cloned into the auth link with the credentials still in it. No flow of ours sends one; the hook now rejects any redirect_to carrying username or password outright and links to the canonical /auth/callback with no next path. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0189cGB2YxptqVxBLJ2RkB5T --------- Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Fable 5.1
parent
e0244b95a7
commit
cb962fae88
@@ -10,13 +10,20 @@ import type { Brand } from '@/lib/branding/resolve'
|
||||
|
||||
vi.mock('@/lib/init', () => ({ ensureInitialized: vi.fn() }))
|
||||
|
||||
const resolveBrandByHostMock = vi.hoisted(() => vi.fn())
|
||||
const resolveBrandResultByHostMock = vi.hoisted(() => vi.fn())
|
||||
vi.mock('@/lib/branding/resolve', () => ({
|
||||
resolveBrandByHost: resolveBrandByHostMock,
|
||||
resolveBrandByHost: vi.fn(),
|
||||
// The one registry read: the trusted-origin resolver classifies the
|
||||
// redirect_to host through it, and the hook reads the sender brand from it.
|
||||
resolveBrandResultByHost: (...args: unknown[]) => resolveBrandResultByHostMock(...args),
|
||||
// Imported by lib/email/brand-sender (not called on the hook path).
|
||||
resolveBrandForCompany: vi.fn(),
|
||||
}))
|
||||
|
||||
const CANONICAL = 'https://app.gnubok.se'
|
||||
/** The one registered brand host in these tests; everything else is unknown. */
|
||||
const BRAND_HOST = 'app.siffra.se'
|
||||
|
||||
vi.mock('@/lib/branding/service', () => ({
|
||||
getBranding: () => ({ appName: 'Accounted', appUrl: 'https://app.gnubok.se' }),
|
||||
}))
|
||||
@@ -87,15 +94,23 @@ function hookPayload(overrides?: {
|
||||
})
|
||||
}
|
||||
|
||||
const ORIGINAL_APP_URL = process.env.NEXT_PUBLIC_APP_URL
|
||||
|
||||
beforeEach(() => {
|
||||
vi.clearAllMocks()
|
||||
process.env.SUPABASE_SEND_EMAIL_HOOK_SECRET = SECRET
|
||||
resolveBrandByHostMock.mockResolvedValue(null)
|
||||
process.env.NEXT_PUBLIC_APP_URL = CANONICAL
|
||||
resolveBrandResultByHostMock.mockImplementation(async (host: string) => ({
|
||||
brand: host === BRAND_HOST ? makeBrand() : null,
|
||||
lookupFailed: false,
|
||||
}))
|
||||
sendEmailMock.mockResolvedValue({ success: true, messageId: 'msg-1' })
|
||||
})
|
||||
|
||||
afterEach(() => {
|
||||
delete process.env.SUPABASE_SEND_EMAIL_HOOK_SECRET
|
||||
if (ORIGINAL_APP_URL === undefined) delete process.env.NEXT_PUBLIC_APP_URL
|
||||
else process.env.NEXT_PUBLIC_APP_URL = ORIGINAL_APP_URL
|
||||
})
|
||||
|
||||
describe('POST /api/auth/email-hook', () => {
|
||||
@@ -138,7 +153,6 @@ describe('POST /api/auth/email-hook', () => {
|
||||
})
|
||||
|
||||
it('brands the mail from the redirect_to host and rides the verified brand sender', async () => {
|
||||
resolveBrandByHostMock.mockResolvedValue(makeBrand())
|
||||
const res = await POST(
|
||||
signedRequest(
|
||||
hookPayload({
|
||||
@@ -150,7 +164,7 @@ describe('POST /api/auth/email-hook', () => {
|
||||
),
|
||||
)
|
||||
expect(res.status).toBe(200)
|
||||
expect(resolveBrandByHostMock).toHaveBeenCalledWith('app.siffra.se')
|
||||
expect(resolveBrandResultByHostMock).toHaveBeenCalledWith('app.siffra.se')
|
||||
|
||||
const options = sendEmailMock.mock.calls[0][0]
|
||||
expect(options.fromName).toBe('Siffra')
|
||||
@@ -163,7 +177,10 @@ describe('POST /api/auth/email-hook', () => {
|
||||
})
|
||||
|
||||
it('uses the via-fallback for a brand without a verified sender domain', async () => {
|
||||
resolveBrandByHostMock.mockResolvedValue(makeBrand({ senderDomainStatus: 'pending' }))
|
||||
resolveBrandResultByHostMock.mockResolvedValue({
|
||||
brand: makeBrand({ senderDomainStatus: 'pending' }),
|
||||
lookupFailed: false,
|
||||
})
|
||||
await POST(
|
||||
signedRequest(
|
||||
hookPayload({
|
||||
@@ -238,4 +255,106 @@ describe('POST /api/auth/email-hook', () => {
|
||||
const res = await POST(signedRequest(hookPayload()))
|
||||
expect(res.status).toBe(500)
|
||||
})
|
||||
|
||||
describe('redirect_to destinations (signature proves the sender, not the destination)', () => {
|
||||
it.each([
|
||||
['an unknown host', 'https://evil.example/auth/callback?next=/reset-password'],
|
||||
['a lookalike of a registered host', 'https://app.siffra.se.evil.example/auth/callback'],
|
||||
['a registered host on a non-default port', 'https://app.siffra.se:8443/auth/callback'],
|
||||
['a credential-bearing URL', 'https://app.siffra.se@evil.example/auth/callback'],
|
||||
// URL.origin drops userinfo: the host alone would pass as trusted.
|
||||
['credentials on a registered host', 'https://evil.example@app.siffra.se/auth/callback?next=/x'],
|
||||
['credentials on the canonical host', 'https://user:pw@app.gnubok.se/auth/callback?next=/x'],
|
||||
['a malformed value', 'not a url'],
|
||||
])('links %s to the canonical callback without the requested path', async (_label, redirectTo) => {
|
||||
const res = await POST(
|
||||
signedRequest(hookPayload({ email_data: { redirect_to: redirectTo } })),
|
||||
)
|
||||
expect(res.status).toBe(200)
|
||||
|
||||
const options = sendEmailMock.mock.calls[0][0]
|
||||
expect(options.text).toContain(
|
||||
'https://app.gnubok.se/auth/callback?token_hash=hash-1&type=recovery',
|
||||
)
|
||||
expect(options.text).not.toContain('evil.example')
|
||||
expect(options.text).not.toContain(':8443')
|
||||
expect(options.text).not.toContain('next=')
|
||||
// Canonical link means canonical sender: brand and destination agree.
|
||||
expect(options.fromName).toBeUndefined()
|
||||
expect(options.fromAddress).toBeUndefined()
|
||||
})
|
||||
|
||||
it('upgrades http on a registered brand host to https and drops the requested path', async () => {
|
||||
await POST(
|
||||
signedRequest(
|
||||
hookPayload({
|
||||
email_data: { redirect_to: 'http://app.siffra.se/auth/callback?next=/settings' },
|
||||
}),
|
||||
),
|
||||
)
|
||||
const options = sendEmailMock.mock.calls[0][0]
|
||||
expect(options.text).toContain(
|
||||
'https://app.siffra.se/auth/callback?token_hash=hash-1&type=recovery',
|
||||
)
|
||||
expect(options.text).not.toContain('http://')
|
||||
expect(options.text).not.toContain('next=')
|
||||
expect(options.fromName).toBe('Siffra')
|
||||
})
|
||||
|
||||
it('keeps the requested path on a registered brand host', async () => {
|
||||
await POST(
|
||||
signedRequest(
|
||||
hookPayload({
|
||||
email_data: { redirect_to: 'https://app.siffra.se/auth/callback?next=%2Freset-password' },
|
||||
}),
|
||||
),
|
||||
)
|
||||
const options = sendEmailMock.mock.calls[0][0]
|
||||
expect(options.text).toContain(
|
||||
'https://app.siffra.se/auth/callback?next=%2Freset-password&token_hash=hash-1',
|
||||
)
|
||||
expect(options.fromName).toBe('Siffra')
|
||||
})
|
||||
|
||||
it('falls back to the canonical callback when redirect_to is missing', async () => {
|
||||
await POST(signedRequest(hookPayload({ email_data: { redirect_to: undefined } })))
|
||||
const options = sendEmailMock.mock.calls[0][0]
|
||||
expect(options.text).toContain('https://app.gnubok.se/auth/callback?token_hash=hash-1')
|
||||
})
|
||||
|
||||
it('returns 500 without sending when the brand read fails after the origin resolved', async () => {
|
||||
// First read (origin classification) succeeds, second (sender) fails:
|
||||
// never platform-branded mail carrying a brand link.
|
||||
resolveBrandResultByHostMock
|
||||
.mockResolvedValueOnce({ brand: makeBrand(), lookupFailed: false })
|
||||
.mockResolvedValueOnce({ brand: null, lookupFailed: true })
|
||||
const res = await POST(
|
||||
signedRequest(
|
||||
hookPayload({ email_data: { redirect_to: 'https://app.siffra.se/auth/callback' } }),
|
||||
),
|
||||
)
|
||||
expect(res.status).toBe(500)
|
||||
expect(sendEmailMock).not.toHaveBeenCalled()
|
||||
})
|
||||
|
||||
it('still sends canonical mail when the brand read fails on the canonical origin', async () => {
|
||||
resolveBrandResultByHostMock.mockResolvedValue({ brand: null, lookupFailed: true })
|
||||
const res = await POST(signedRequest(hookPayload()))
|
||||
expect(res.status).toBe(200)
|
||||
const options = sendEmailMock.mock.calls[0][0]
|
||||
expect(options.text).toContain('https://app.gnubok.se/auth/callback?next=%2Freset-password')
|
||||
expect(options.fromName).toBeUndefined()
|
||||
})
|
||||
|
||||
it('returns 500 without sending when the brand registry cannot be read', async () => {
|
||||
resolveBrandResultByHostMock.mockResolvedValue({ brand: null, lookupFailed: true })
|
||||
const res = await POST(
|
||||
signedRequest(
|
||||
hookPayload({ email_data: { redirect_to: 'https://app.siffra.se/auth/callback' } }),
|
||||
),
|
||||
)
|
||||
expect(res.status).toBe(500)
|
||||
expect(sendEmailMock).not.toHaveBeenCalled()
|
||||
})
|
||||
})
|
||||
})
|
||||
|
||||
@@ -3,10 +3,15 @@ import { ensureInitialized } from '@/lib/init'
|
||||
import { createLogger } from '@/lib/logger'
|
||||
import { getEmailService } from '@/lib/email/service'
|
||||
import { getBranding } from '@/lib/branding/service'
|
||||
import { resolveBrandByHost } from '@/lib/branding/resolve'
|
||||
import { resolveBrandResultByHost } from '@/lib/branding/resolve'
|
||||
import { getSenderForBrand } from '@/lib/email/brand-sender'
|
||||
import { buildAuthEmail } from '@/lib/email/auth-templates'
|
||||
import { verifyStandardWebhookSignature } from '@/lib/email/standard-webhook'
|
||||
import {
|
||||
BrandLookupFailedError,
|
||||
getCanonicalAppOrigin,
|
||||
resolveTrustedAppOrigin,
|
||||
} from '@/lib/domains/trusted-app-origin'
|
||||
|
||||
// Loads the email extension so getEmailService() returns the Resend
|
||||
// implementation instead of the noop default.
|
||||
@@ -22,14 +27,21 @@ const log = createLogger('auth-email-hook')
|
||||
* sending auth mail itself and this endpoint sends every auth mail (signup
|
||||
* confirmation, recovery, magic link, invite, email change, reauthentication)
|
||||
* through the platform email service, branded per the requesting host: the
|
||||
* brand is resolved from the redirect_to origin via resolveBrandByHost, so a
|
||||
* brand is resolved from the trusted redirect_to origin, so a
|
||||
* reset requested on app.partner.se is sent in the partner's brand and links
|
||||
* back to app.partner.se. Unknown hosts get canonical platform mail.
|
||||
*
|
||||
* Unauthenticated by design (server-to-server): authenticity comes from the
|
||||
* Standard Webhooks signature, not a session, exactly like the Stripe and
|
||||
* Resend webhook routes. The raw body is verified byte-for-byte before
|
||||
* parsing. This endpoint is availability-critical once the hook is enabled:
|
||||
* parsing. The signature proves WHO sent the payload, not that every
|
||||
* destination in it should be followed: redirect_to is GoTrue's already
|
||||
* allowlisted referrer, but that allowlist is a glob configured by hand, so
|
||||
* the origin is resolved here again through lib/domains/trusted-app-origin
|
||||
* (canonical, this deployment's own Vercel hosts, or a registered brand
|
||||
* domain). Anything else gets a canonical link, and the token never rides
|
||||
* to a host this deployment does not serve. This endpoint is
|
||||
* availability-critical once the hook is enabled:
|
||||
* any internal failure returns 500 so Supabase retries (up to 3 times within
|
||||
* a 5 second budget); success returns 200 {} fast.
|
||||
*
|
||||
@@ -71,8 +83,13 @@ interface SendEmailHookPayload {
|
||||
* /auth/callback consumes token_hash + type server-side and then honors the
|
||||
* `next` path. If redirect_to already points at /auth/callback (our client
|
||||
* flows do), its query (e.g. next=/reset-password) is preserved.
|
||||
*
|
||||
* `origin` is the already-trusted application origin; `redirectUrl` is the
|
||||
* requested redirect_to only when it sits on that origin, else null (the
|
||||
* link then lands on the origin's /auth/callback with no `next`).
|
||||
*/
|
||||
function buildActionUrl(
|
||||
origin: string,
|
||||
redirectUrl: URL | null,
|
||||
tokenHash: string,
|
||||
actionType: string,
|
||||
@@ -82,7 +99,7 @@ function buildActionUrl(
|
||||
if (redirectUrl && redirectUrl.pathname === '/auth/callback') {
|
||||
url = new URL(redirectUrl.toString())
|
||||
} else {
|
||||
url = new URL('/auth/callback', redirectUrl ? redirectUrl.origin : getBranding().appUrl)
|
||||
url = new URL('/auth/callback', origin)
|
||||
if (redirectUrl) {
|
||||
const next = redirectUrl.pathname + redirectUrl.search
|
||||
if (next && next !== '/') url.searchParams.set('next', next)
|
||||
@@ -93,6 +110,47 @@ function buildActionUrl(
|
||||
return url.toString()
|
||||
}
|
||||
|
||||
/**
|
||||
* The requested redirect_to, kept only when its origin is one this
|
||||
* deployment serves. The comparison is on the resolved origin, so an http
|
||||
* link to a hosted domain, a lookalike host, a non-default port or a
|
||||
* credential-bearing URL all collapse to the canonical /auth/callback.
|
||||
* Throws BrandLookupFailedError when the brands table cannot be read.
|
||||
*/
|
||||
async function resolveRedirect(
|
||||
requested: string | undefined,
|
||||
): Promise<{ origin: string; redirectUrl: URL | null }> {
|
||||
let requestedUrl: URL | null = null
|
||||
if (requested) {
|
||||
try {
|
||||
requestedUrl = new URL(requested)
|
||||
} catch {
|
||||
requestedUrl = null
|
||||
}
|
||||
}
|
||||
// URL.origin drops userinfo, so a credential-bearing redirect on a served
|
||||
// host would pass the origin comparison and be cloned into the link with
|
||||
// the credentials still in it. No flow of ours ever sends one: treat it as
|
||||
// untrusted outright (canonical link, no next), never as a served host.
|
||||
if (requestedUrl && (requestedUrl.username || requestedUrl.password)) {
|
||||
log.warn('redirect_to carries credentials; linking to the canonical origin', {
|
||||
host: requestedUrl.hostname,
|
||||
})
|
||||
requestedUrl = null
|
||||
}
|
||||
const origin = await resolveTrustedAppOrigin(requestedUrl?.origin ?? null)
|
||||
if (requestedUrl && requestedUrl.origin === origin) {
|
||||
return { origin, redirectUrl: requestedUrl }
|
||||
}
|
||||
if (requestedUrl) {
|
||||
// Hostname only: the URL may carry a query, never log the token side.
|
||||
log.warn('redirect_to origin is not a served host; linking to the canonical origin', {
|
||||
host: requestedUrl.hostname,
|
||||
})
|
||||
}
|
||||
return { origin, redirectUrl: null }
|
||||
}
|
||||
|
||||
export async function POST(request: Request) {
|
||||
const secret = process.env.SUPABASE_SEND_EMAIL_HOOK_SECRET
|
||||
if (!secret) {
|
||||
@@ -126,16 +184,29 @@ export async function POST(request: Request) {
|
||||
return NextResponse.json({ error: 'Missing recipient' }, { status: 400 })
|
||||
}
|
||||
|
||||
// Brand from the requesting host: redirect_to carries the tenant origin.
|
||||
let redirectUrl: URL | null = null
|
||||
if (emailData.redirect_to) {
|
||||
try {
|
||||
redirectUrl = new URL(emailData.redirect_to)
|
||||
} catch {
|
||||
redirectUrl = null
|
||||
}
|
||||
// Brand from the RESOLVED host: redirect_to carries the tenant origin, and
|
||||
// the sender identity must match the host the link lands on. A lookup
|
||||
// failure is a 500 so Supabase retries rather than sending a mail whose
|
||||
// link would land on the wrong domain.
|
||||
let resolved: Awaited<ReturnType<typeof resolveRedirect>>
|
||||
try {
|
||||
resolved = await resolveRedirect(emailData.redirect_to)
|
||||
} catch (err) {
|
||||
if (!(err instanceof BrandLookupFailedError)) throw err
|
||||
log.error('brand lookup failed while resolving redirect_to', err, { host: err.host })
|
||||
return NextResponse.json({ error: 'Origin lookup failed' }, { status: 500 })
|
||||
}
|
||||
const brand = redirectUrl ? await resolveBrandByHost(redirectUrl.hostname) : null
|
||||
const { origin, redirectUrl } = resolved
|
||||
// A brand host whose row cannot be read right now (a second registry read
|
||||
// can fail after the first succeeded) must not get platform-branded mail
|
||||
// carrying a brand link: 500, Supabase retries. On the canonical origin a
|
||||
// failed read is the platform sender either way, so it does not block.
|
||||
const brandResult = await resolveBrandResultByHost(new URL(origin).hostname)
|
||||
if (brandResult.lookupFailed && origin !== getCanonicalAppOrigin()) {
|
||||
log.error('brand lookup failed for the resolved origin', undefined, { origin })
|
||||
return NextResponse.json({ error: 'Origin lookup failed' }, { status: 500 })
|
||||
}
|
||||
const brand = brandResult.brand
|
||||
const sender = getSenderForBrand(brand)
|
||||
const appName = brand?.appName ?? getBranding().appName
|
||||
|
||||
@@ -158,13 +229,13 @@ export async function POST(request: Request) {
|
||||
mails.push({
|
||||
to: newEmail,
|
||||
actionType: 'email_change',
|
||||
actionUrl: buildActionUrl(redirectUrl, emailData.token_hash, 'email_change'),
|
||||
actionUrl: buildActionUrl(origin, redirectUrl, emailData.token_hash, 'email_change'),
|
||||
})
|
||||
if (emailData.token_hash_new) {
|
||||
mails.push({
|
||||
to: recipient,
|
||||
actionType: 'email_change_current',
|
||||
actionUrl: buildActionUrl(redirectUrl, emailData.token_hash_new, 'email_change'),
|
||||
actionUrl: buildActionUrl(origin, redirectUrl, emailData.token_hash_new, 'email_change'),
|
||||
})
|
||||
}
|
||||
} else {
|
||||
@@ -174,7 +245,7 @@ export async function POST(request: Request) {
|
||||
mails.push({
|
||||
to: recipient,
|
||||
actionType,
|
||||
actionUrl: buildActionUrl(redirectUrl, emailData.token_hash, actionType),
|
||||
actionUrl: buildActionUrl(origin, redirectUrl, emailData.token_hash, actionType),
|
||||
})
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user