Skip to content

Reject reserved identity email subdomains - #28

Merged
nedtwigg merged 1 commit into
mainfrom
fix/reserved-identity-email-namespace
Sep 29, 2026
Merged

nedtwigg merged 1 commit into
mainfrom
fix/reserved-identity-email-namespace

Conversation

@nedtwigg

Copy link
Copy Markdown
Member

An address such as sub@a.identity.pgstencil.invalid bypassed the reserved-email guard because it matched only the exact @identity.pgstencil.invalid suffix. Match the domain and all subdomains, case-insensitively and with an optional DNS root dot, so the existing email-route, delivery, OAuth, and response-redaction guards cover the whole namespace. Generated provider-only identity addresses remain unchanged.

Add regression tests for both email routes, rejected OAuth-supplied addresses, mixed case, trailing dots, and domain lookalikes. Verify rejected email requests send no messages and create no users or verification records.

Fixes #27.

Validation:

  • Confirmed the new unit regression fails on the original implementation.
  • Unit and Better Auth integration suites: 11 files, 84 tests passed (including Workers).
  • TypeScript type checking, formatting checks for changed files, and git diff --check passed.
  • Ran the installed tools directly because the local pnpm launcher fails with ENOEXEC.

@nedtwigg
nedtwigg merged commit e429025 into main Sep 29, 2026
1 check passed
@nedtwigg
nedtwigg deleted the fix/reserved-identity-email-namespace branch September 29, 2026 15:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[security-audit] FAIL on 2026-09-29

1 participant