Skip to content

fix(auth): restore social registration and explicit linking - #12

Merged
SirNarsh merged 2 commits into
mainfrom
fix/social-registration-metadata
Oct 3, 2026
Merged

SirNarsh merged 2 commits into
mainfrom
fix/social-registration-metadata

Conversation

@SirNarsh

@SirNarsh SirNarsh commented Oct 3, 2026

Copy link
Copy Markdown
Member

Summary

  • Cast email metadata parameters to text in automatic registration, explicit provider linking, and external email enrollment.
  • Preserve the existing public-registration default and invite-only policy, explicit same-email linking, and application isolation.
  • Clarify registration behavior in admin help and documentation.
  • Require PostgreSQL registration and enrollment regressions to execute in CI.

Verification

  • Reproduced the PostgreSQL parameter-type failure before the fix.
  • PostgreSQL regressions: normalized metadata, repeat login, explicit linking, same-email rejection, application isolation, invite-only blocking, existing-user login, enrollment success, and replay rejection.
  • Go 1.25.13: full race suite with PostgreSQL, go vet, and govulncheck passed (no reachable vulnerabilities).
  • Admin typecheck, lint, and static build passed; existing image-element lint warning unchanged.
  • Gitleaks history and staged scans passed.

No database migration or API-contract change. Live provider verification and deployment are not included in these local results.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Enrollment verification can bypass a newly enabled invite-only policy, and its test cleanup leaves domain-event records behind.

Review effort: Balanced
Findings: 1 High severity · 1 Medium severity

Open (2)
What changed in this PR

Fixes PostgreSQL social-registration metadata typing while documenting and testing registration/linking behavior.

Changes:

  • Cast identity email metadata parameters to PostgreSQL text.
  • Add registration, linking, isolation, enrollment, and replay regressions.
  • Expand admin documentation and enforce CI execution.
File Description
web/​app/​page.tsx Clarifies registration policy help.
internal/​httpapi/​google_auth.go Fixes email metadata parameter typing.
internal/​httpapi/​external_identity_registration_integration_test.go Adds social identity regressions.
internal/​httpapi/​external_email_enrollment.go Fixes enrollment metadata typing.
internal/​httpapi/​external_email_enrollment_integration_test.go Tests enrollment success and replay rejection.
docs/​application-configuration.md Documents registration and linking behavior.
.github/​workflows/​verify.yml Requires regressions to execute in CI.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread internal/httpapi/external_email_enrollment.go
Comment thread internal/httpapi/external_email_enrollment_integration_test.go Outdated

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The changes consistently address PostgreSQL typing and registration-policy enforcement with focused regression coverage.

Review effort: Balanced
Findings: None

Resolved since last review (2)

@SirNarsh
SirNarsh merged commit 1509724 into main Oct 3, 2026
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants