fix(auth): resolve BankID confirmation and email-hook link hosts through the trusted-origin registry (#2380)

* fix(auth): resolve BankID confirmation and email-hook link hosts through the trusted-origin registry

The BankID confirmation mail built its /auth/callback link from the raw
forwarded host and protocol; it is the one auth link GoTrue's redirect
allowlist never sees, since the link is minted here and sent through
Resend. The Send Email hook followed GoTrue's redirect_to verbatim: the
webhook signature proves who sent the payload, not that every destination
in it should be followed, and the GoTrue allowlist is a hand-configured
glob.

Both now resolve the destination through lib/domains/trusted-app-origin
like every other auth link (canonical, this deployment's own Vercel hosts,
or a registered brands.domain). Unknown, lookalike, credential-bearing,
non-default-port and malformed destinations collapse to the canonical
/auth/callback with no next path; a registered brand host over http is
upgraded to https. Brand sender identity is taken from the RESOLVED host,
so mail branding and link destination always agree. A brands-table read
failure refuses instead of mailing a wrong-host link: the BankID helper
returns step resolve_origin (signup rolls back, login re-send logs), the
hook answers 500 so Supabase retries.

Drops the proto parameter from the BankID helper; the resolver owns the
scheme.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0189cGB2YxptqVxBLJ2RkB5T

* fix(auth): read the sender brand once, failure-aware, before minting or sending auth mail

CodeRabbit: resolveTrustedAppOrigin could classify a brand host, then the
separate resolveBrandByHost read for the sender could fail and return null,
so a brand link went out with the platform sender; the BankID helper had
already minted the magic link by then. Both sites now read the brand with
resolveBrandResultByHost on the resolved host and refuse on a failed read
for any non-canonical origin (BankID: step resolve_origin before
generateLink; hook: 500 so Supabase retries). On the canonical origin a
failed read is the platform sender either way, so mail still goes out.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0189cGB2YxptqVxBLJ2RkB5T

* fix(auth): treat a credential-bearing redirect_to as untrusted in the email hook

Superagent P2: URL.origin drops userinfo, so a redirect_to with credentials
on a served host passed the origin comparison and was cloned into the auth
link with the credentials still in it. No flow of ours sends one; the hook
now rejects any redirect_to carrying username or password outright and
links to the canonical /auth/callback with no next path.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0189cGB2YxptqVxBLJ2RkB5T

---------

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
Mattsson
2026-09-07 16:29:29 +02:00
committed by GitHub
co-authored by Claude Fable 5.1
parent e0244b95a7
commit cb962fae88
7 changed files with 376 additions and 74 deletions
+125 -6
View File
@@ -10,13 +10,20 @@ import type { Brand } from '@/lib/branding/resolve'
vi.mock('@/lib/init', () => ({ ensureInitialized: vi.fn() }))
const resolveBrandByHostMock = vi.hoisted(() => vi.fn())
const resolveBrandResultByHostMock = vi.hoisted(() => vi.fn())
vi.mock('@/lib/branding/resolve', () => ({
resolveBrandByHost: resolveBrandByHostMock,
resolveBrandByHost: vi.fn(),
// The one registry read: the trusted-origin resolver classifies the
// redirect_to host through it, and the hook reads the sender brand from it.
resolveBrandResultByHost: (...args: unknown[]) => resolveBrandResultByHostMock(...args),
// Imported by lib/email/brand-sender (not called on the hook path).
resolveBrandForCompany: vi.fn(),
}))
const CANONICAL = 'https://app.gnubok.se'
/** The one registered brand host in these tests; everything else is unknown. */
const BRAND_HOST = 'app.siffra.se'
vi.mock('@/lib/branding/service', () => ({
getBranding: () => ({ appName: 'Accounted', appUrl: 'https://app.gnubok.se' }),
}))
@@ -87,15 +94,23 @@ function hookPayload(overrides?: {
})
}
const ORIGINAL_APP_URL = process.env.NEXT_PUBLIC_APP_URL
beforeEach(() => {
vi.clearAllMocks()
process.env.SUPABASE_SEND_EMAIL_HOOK_SECRET = SECRET
resolveBrandByHostMock.mockResolvedValue(null)
process.env.NEXT_PUBLIC_APP_URL = CANONICAL
resolveBrandResultByHostMock.mockImplementation(async (host: string) => ({
brand: host === BRAND_HOST ? makeBrand() : null,
lookupFailed: false,
}))
sendEmailMock.mockResolvedValue({ success: true, messageId: 'msg-1' })
})
afterEach(() => {
delete process.env.SUPABASE_SEND_EMAIL_HOOK_SECRET
if (ORIGINAL_APP_URL === undefined) delete process.env.NEXT_PUBLIC_APP_URL
else process.env.NEXT_PUBLIC_APP_URL = ORIGINAL_APP_URL
})
describe('POST /api/auth/email-hook', () => {
@@ -138,7 +153,6 @@ describe('POST /api/auth/email-hook', () => {
})
it('brands the mail from the redirect_to host and rides the verified brand sender', async () => {
resolveBrandByHostMock.mockResolvedValue(makeBrand())
const res = await POST(
signedRequest(
hookPayload({
@@ -150,7 +164,7 @@ describe('POST /api/auth/email-hook', () => {
),
)
expect(res.status).toBe(200)
expect(resolveBrandByHostMock).toHaveBeenCalledWith('app.siffra.se')
expect(resolveBrandResultByHostMock).toHaveBeenCalledWith('app.siffra.se')
const options = sendEmailMock.mock.calls[0][0]
expect(options.fromName).toBe('Siffra')
@@ -163,7 +177,10 @@ describe('POST /api/auth/email-hook', () => {
})
it('uses the via-fallback for a brand without a verified sender domain', async () => {
resolveBrandByHostMock.mockResolvedValue(makeBrand({ senderDomainStatus: 'pending' }))
resolveBrandResultByHostMock.mockResolvedValue({
brand: makeBrand({ senderDomainStatus: 'pending' }),
lookupFailed: false,
})
await POST(
signedRequest(
hookPayload({
@@ -238,4 +255,106 @@ describe('POST /api/auth/email-hook', () => {
const res = await POST(signedRequest(hookPayload()))
expect(res.status).toBe(500)
})
describe('redirect_to destinations (signature proves the sender, not the destination)', () => {
it.each([
['an unknown host', 'https://evil.example/auth/callback?next=/reset-password'],
['a lookalike of a registered host', 'https://app.siffra.se.evil.example/auth/callback'],
['a registered host on a non-default port', 'https://app.siffra.se:8443/auth/callback'],
['a credential-bearing URL', 'https://app.siffra.se@evil.example/auth/callback'],
// URL.origin drops userinfo: the host alone would pass as trusted.
['credentials on a registered host', 'https://evil.example@app.siffra.se/auth/callback?next=/x'],
['credentials on the canonical host', 'https://user:pw@app.gnubok.se/auth/callback?next=/x'],
['a malformed value', 'not a url'],
])('links %s to the canonical callback without the requested path', async (_label, redirectTo) => {
const res = await POST(
signedRequest(hookPayload({ email_data: { redirect_to: redirectTo } })),
)
expect(res.status).toBe(200)
const options = sendEmailMock.mock.calls[0][0]
expect(options.text).toContain(
'https://app.gnubok.se/auth/callback?token_hash=hash-1&type=recovery',
)
expect(options.text).not.toContain('evil.example')
expect(options.text).not.toContain(':8443')
expect(options.text).not.toContain('next=')
// Canonical link means canonical sender: brand and destination agree.
expect(options.fromName).toBeUndefined()
expect(options.fromAddress).toBeUndefined()
})
it('upgrades http on a registered brand host to https and drops the requested path', async () => {
await POST(
signedRequest(
hookPayload({
email_data: { redirect_to: 'http://app.siffra.se/auth/callback?next=/settings' },
}),
),
)
const options = sendEmailMock.mock.calls[0][0]
expect(options.text).toContain(
'https://app.siffra.se/auth/callback?token_hash=hash-1&type=recovery',
)
expect(options.text).not.toContain('http://')
expect(options.text).not.toContain('next=')
expect(options.fromName).toBe('Siffra')
})
it('keeps the requested path on a registered brand host', async () => {
await POST(
signedRequest(
hookPayload({
email_data: { redirect_to: 'https://app.siffra.se/auth/callback?next=%2Freset-password' },
}),
),
)
const options = sendEmailMock.mock.calls[0][0]
expect(options.text).toContain(
'https://app.siffra.se/auth/callback?next=%2Freset-password&token_hash=hash-1',
)
expect(options.fromName).toBe('Siffra')
})
it('falls back to the canonical callback when redirect_to is missing', async () => {
await POST(signedRequest(hookPayload({ email_data: { redirect_to: undefined } })))
const options = sendEmailMock.mock.calls[0][0]
expect(options.text).toContain('https://app.gnubok.se/auth/callback?token_hash=hash-1')
})
it('returns 500 without sending when the brand read fails after the origin resolved', async () => {
// First read (origin classification) succeeds, second (sender) fails:
// never platform-branded mail carrying a brand link.
resolveBrandResultByHostMock
.mockResolvedValueOnce({ brand: makeBrand(), lookupFailed: false })
.mockResolvedValueOnce({ brand: null, lookupFailed: true })
const res = await POST(
signedRequest(
hookPayload({ email_data: { redirect_to: 'https://app.siffra.se/auth/callback' } }),
),
)
expect(res.status).toBe(500)
expect(sendEmailMock).not.toHaveBeenCalled()
})
it('still sends canonical mail when the brand read fails on the canonical origin', async () => {
resolveBrandResultByHostMock.mockResolvedValue({ brand: null, lookupFailed: true })
const res = await POST(signedRequest(hookPayload()))
expect(res.status).toBe(200)
const options = sendEmailMock.mock.calls[0][0]
expect(options.text).toContain('https://app.gnubok.se/auth/callback?next=%2Freset-password')
expect(options.fromName).toBeUndefined()
})
it('returns 500 without sending when the brand registry cannot be read', async () => {
resolveBrandResultByHostMock.mockResolvedValue({ brand: null, lookupFailed: true })
const res = await POST(
signedRequest(
hookPayload({ email_data: { redirect_to: 'https://app.siffra.se/auth/callback' } }),
),
)
expect(res.status).toBe(500)
expect(sendEmailMock).not.toHaveBeenCalled()
})
})
})
+87 -16
View File
@@ -3,10 +3,15 @@ import { ensureInitialized } from '@/lib/init'
import { createLogger } from '@/lib/logger'
import { getEmailService } from '@/lib/email/service'
import { getBranding } from '@/lib/branding/service'
import { resolveBrandByHost } from '@/lib/branding/resolve'
import { resolveBrandResultByHost } from '@/lib/branding/resolve'
import { getSenderForBrand } from '@/lib/email/brand-sender'
import { buildAuthEmail } from '@/lib/email/auth-templates'
import { verifyStandardWebhookSignature } from '@/lib/email/standard-webhook'
import {
BrandLookupFailedError,
getCanonicalAppOrigin,
resolveTrustedAppOrigin,
} from '@/lib/domains/trusted-app-origin'
// Loads the email extension so getEmailService() returns the Resend
// implementation instead of the noop default.
@@ -22,14 +27,21 @@ const log = createLogger('auth-email-hook')
* sending auth mail itself and this endpoint sends every auth mail (signup
* confirmation, recovery, magic link, invite, email change, reauthentication)
* through the platform email service, branded per the requesting host: the
* brand is resolved from the redirect_to origin via resolveBrandByHost, so a
* brand is resolved from the trusted redirect_to origin, so a
* reset requested on app.partner.se is sent in the partner's brand and links
* back to app.partner.se. Unknown hosts get canonical platform mail.
*
* Unauthenticated by design (server-to-server): authenticity comes from the
* Standard Webhooks signature, not a session, exactly like the Stripe and
* Resend webhook routes. The raw body is verified byte-for-byte before
* parsing. This endpoint is availability-critical once the hook is enabled:
* parsing. The signature proves WHO sent the payload, not that every
* destination in it should be followed: redirect_to is GoTrue's already
* allowlisted referrer, but that allowlist is a glob configured by hand, so
* the origin is resolved here again through lib/domains/trusted-app-origin
* (canonical, this deployment's own Vercel hosts, or a registered brand
* domain). Anything else gets a canonical link, and the token never rides
* to a host this deployment does not serve. This endpoint is
* availability-critical once the hook is enabled:
* any internal failure returns 500 so Supabase retries (up to 3 times within
* a 5 second budget); success returns 200 {} fast.
*
@@ -71,8 +83,13 @@ interface SendEmailHookPayload {
* /auth/callback consumes token_hash + type server-side and then honors the
* `next` path. If redirect_to already points at /auth/callback (our client
* flows do), its query (e.g. next=/reset-password) is preserved.
*
* `origin` is the already-trusted application origin; `redirectUrl` is the
* requested redirect_to only when it sits on that origin, else null (the
* link then lands on the origin's /auth/callback with no `next`).
*/
function buildActionUrl(
origin: string,
redirectUrl: URL | null,
tokenHash: string,
actionType: string,
@@ -82,7 +99,7 @@ function buildActionUrl(
if (redirectUrl && redirectUrl.pathname === '/auth/callback') {
url = new URL(redirectUrl.toString())
} else {
url = new URL('/auth/callback', redirectUrl ? redirectUrl.origin : getBranding().appUrl)
url = new URL('/auth/callback', origin)
if (redirectUrl) {
const next = redirectUrl.pathname + redirectUrl.search
if (next && next !== '/') url.searchParams.set('next', next)
@@ -93,6 +110,47 @@ function buildActionUrl(
return url.toString()
}
/**
* The requested redirect_to, kept only when its origin is one this
* deployment serves. The comparison is on the resolved origin, so an http
* link to a hosted domain, a lookalike host, a non-default port or a
* credential-bearing URL all collapse to the canonical /auth/callback.
* Throws BrandLookupFailedError when the brands table cannot be read.
*/
async function resolveRedirect(
requested: string | undefined,
): Promise<{ origin: string; redirectUrl: URL | null }> {
let requestedUrl: URL | null = null
if (requested) {
try {
requestedUrl = new URL(requested)
} catch {
requestedUrl = null
}
}
// URL.origin drops userinfo, so a credential-bearing redirect on a served
// host would pass the origin comparison and be cloned into the link with
// the credentials still in it. No flow of ours ever sends one: treat it as
// untrusted outright (canonical link, no next), never as a served host.
if (requestedUrl && (requestedUrl.username || requestedUrl.password)) {
log.warn('redirect_to carries credentials; linking to the canonical origin', {
host: requestedUrl.hostname,
})
requestedUrl = null
}
const origin = await resolveTrustedAppOrigin(requestedUrl?.origin ?? null)
if (requestedUrl && requestedUrl.origin === origin) {
return { origin, redirectUrl: requestedUrl }
}
if (requestedUrl) {
// Hostname only: the URL may carry a query, never log the token side.
log.warn('redirect_to origin is not a served host; linking to the canonical origin', {
host: requestedUrl.hostname,
})
}
return { origin, redirectUrl: null }
}
export async function POST(request: Request) {
const secret = process.env.SUPABASE_SEND_EMAIL_HOOK_SECRET
if (!secret) {
@@ -126,16 +184,29 @@ export async function POST(request: Request) {
return NextResponse.json({ error: 'Missing recipient' }, { status: 400 })
}
// Brand from the requesting host: redirect_to carries the tenant origin.
let redirectUrl: URL | null = null
if (emailData.redirect_to) {
try {
redirectUrl = new URL(emailData.redirect_to)
} catch {
redirectUrl = null
}
// Brand from the RESOLVED host: redirect_to carries the tenant origin, and
// the sender identity must match the host the link lands on. A lookup
// failure is a 500 so Supabase retries rather than sending a mail whose
// link would land on the wrong domain.
let resolved: Awaited<ReturnType<typeof resolveRedirect>>
try {
resolved = await resolveRedirect(emailData.redirect_to)
} catch (err) {
if (!(err instanceof BrandLookupFailedError)) throw err
log.error('brand lookup failed while resolving redirect_to', err, { host: err.host })
return NextResponse.json({ error: 'Origin lookup failed' }, { status: 500 })
}
const brand = redirectUrl ? await resolveBrandByHost(redirectUrl.hostname) : null
const { origin, redirectUrl } = resolved
// A brand host whose row cannot be read right now (a second registry read
// can fail after the first succeeded) must not get platform-branded mail
// carrying a brand link: 500, Supabase retries. On the canonical origin a
// failed read is the platform sender either way, so it does not block.
const brandResult = await resolveBrandResultByHost(new URL(origin).hostname)
if (brandResult.lookupFailed && origin !== getCanonicalAppOrigin()) {
log.error('brand lookup failed for the resolved origin', undefined, { origin })
return NextResponse.json({ error: 'Origin lookup failed' }, { status: 500 })
}
const brand = brandResult.brand
const sender = getSenderForBrand(brand)
const appName = brand?.appName ?? getBranding().appName
@@ -158,13 +229,13 @@ export async function POST(request: Request) {
mails.push({
to: newEmail,
actionType: 'email_change',
actionUrl: buildActionUrl(redirectUrl, emailData.token_hash, 'email_change'),
actionUrl: buildActionUrl(origin, redirectUrl, emailData.token_hash, 'email_change'),
})
if (emailData.token_hash_new) {
mails.push({
to: recipient,
actionType: 'email_change_current',
actionUrl: buildActionUrl(redirectUrl, emailData.token_hash_new, 'email_change'),
actionUrl: buildActionUrl(origin, redirectUrl, emailData.token_hash_new, 'email_change'),
})
}
} else {
@@ -174,7 +245,7 @@ export async function POST(request: Request) {
mails.push({
to: recipient,
actionType,
actionUrl: buildActionUrl(redirectUrl, emailData.token_hash, actionType),
actionUrl: buildActionUrl(origin, redirectUrl, emailData.token_hash, actionType),
})
}