mirror of
https://github.com/better-auth/better-auth.git
synced 2026-07-27 16:53:02 -05:00
Re-applies five main fixes onto next's rebuilt SSO routes. next's refactor kept the supporting helpers (the SSRF host check, the SAMLSessionRecord token field) but dropped the call sites, so the merge left them present yet unused. This wires them back. - #9574: registerSSOProvider and updateSSOProvider now run validateSkipDiscoveryEndpoints on user-supplied OIDC endpoints, rejecting private/link-local hosts (for example 169.254.169.254). The merge included the helper but never called it, leaving advisory GHSA-5rr4-8452-hf4v open on next. Validation runs even without skipDiscovery. - #9220: registering an SSO provider requires an organization owner/admin role when the organization plugin is active, blocking a low-privilege member from registering a malicious IdP. - #9818: SAML Single Logout revokes the session by token; the SAML session record now carries the session token. - #9722: the OIDC callback error redirect encodes the error value. - #9702: a before-callback hook rejection in the OIDC and SAML callbacks redirects to the per-flow errorURL with the hook's code, instead of surfacing a raw response. Two stale IDP-bounce assertions are updated to next's migrated state-error vocabulary (state_not_found). All SSO regression suites pass (SSRF, org-admin, SLO, hook-rejection, encoding). (cherry picked from commit c3b238f71a6f66914f12db5f615504e2cf855bfc)