Gustavo Valverde 9247cb8528 fix(sso): enforce SSRF validation, org-admin registration, SLO-by-token, and error encoding on refactored routes (#9574, #9220, #9818, #9722, #9702)
Re-applies five main fixes onto next's rebuilt SSO routes. next's refactor
kept the supporting helpers (the SSRF host check, the SAMLSessionRecord
token field) but dropped the call sites, so the merge left them present yet
unused. This wires them back.

- #9574: registerSSOProvider and updateSSOProvider now run
  validateSkipDiscoveryEndpoints on user-supplied OIDC endpoints, rejecting
  private/link-local hosts (for example 169.254.169.254). The merge included
  the helper but never called it, leaving advisory GHSA-5rr4-8452-hf4v open
  on next. Validation runs even without skipDiscovery.
- #9220: registering an SSO provider requires an organization owner/admin
  role when the organization plugin is active, blocking a low-privilege
  member from registering a malicious IdP.
- #9818: SAML Single Logout revokes the session by token; the SAML session
  record now carries the session token.
- #9722: the OIDC callback error redirect encodes the error value.
- #9702: a before-callback hook rejection in the OIDC and SAML callbacks
  redirects to the per-flow errorURL with the hook's code, instead of
  surfacing a raw response.

Two stale IDP-bounce assertions are updated to next's migrated state-error
vocabulary (state_not_found). All SSO regression suites pass (SSRF,
org-admin, SLO, hook-rejection, encoding).

(cherry picked from commit c3b238f71a6f66914f12db5f615504e2cf855bfc)
2026-05-31 00:10:48 +01:00
2026-05-31 00:10:16 +01:00
2026-05-31 00:10:16 +01:00
2026-05-31 00:10:16 +01:00
2026-04-23 19:50:25 +00:00
2026-04-23 19:50:25 +00:00
2026-04-23 19:50:25 +00:00
2026-04-18 23:04:27 -07:00

Better Auth

Better Auth is a framework-agnostic authentication (and authorization) framework for TypeScript. It provides a comprehensive set of features out of the box and includes a plugin ecosystem that simplifies adding advanced functionalities with minimal code in a short amount of time. Whether you need 2FA, multi-tenant support, or other complex features, it lets you focus on building your actual application instead of reinventing the wheel.

Why Better Auth

Authentication in the TypeScript ecosystem is a half-solved problem. Other open-source libraries often require a lot of additional code for anything beyond basic authentication. Rather than just pushing third-party services as the solution, I believe we can do better as a community—hence, Better Auth.

Contribution

Better Auth is a free and open source project licensed under the MIT License. You are free to do whatever you want with it.

You could help continuing its development by:

Security

If you discover a security vulnerability within Better Auth, please send an e-mail to security@better-auth.com.

All reports will be promptly addressed, and you'll be credited accordingly.

S
Description
No description provided
Readme
247 MiB
Latest
2026-04-16 05:05:30 -05:00
Languages
TypeScript 99.4%
CSS 0.3%
MDX 0.2%