fix(auth): address code review feedback - sanitize error messages, remove unused import
Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
This commit is contained in:
+3
-2
@@ -305,7 +305,8 @@ def _normalize_social_userinfo(provider: str, token: dict, raw_userinfo: dict |
|
|||||||
|
|
||||||
Args:
|
Args:
|
||||||
provider: The social provider key (google, microsoft, apple, dropbox).
|
provider: The social provider key (google, microsoft, apple, dropbox).
|
||||||
token: The OAuth token response from the provider.
|
token: The OAuth token response from the provider. Included for future
|
||||||
|
provider-specific claim extraction (e.g. ``id_token`` claims).
|
||||||
raw_userinfo: The raw userinfo dict (may be None for providers without standard OIDC userinfo).
|
raw_userinfo: The raw userinfo dict (may be None for providers without standard OIDC userinfo).
|
||||||
|
|
||||||
Returns:
|
Returns:
|
||||||
@@ -415,7 +416,7 @@ async def social_callback(request: Request, provider: str, db: Session = Depends
|
|||||||
except Exception as e:
|
except Exception as e:
|
||||||
logger.warning("[SECURITY] SOCIAL_LOGIN_FAILURE provider=%s error=%s", provider, type(e).__name__)
|
logger.warning("[SECURITY] SOCIAL_LOGIN_FAILURE provider=%s error=%s", provider, type(e).__name__)
|
||||||
return RedirectResponse(
|
return RedirectResponse(
|
||||||
url=f"/login?error=Social+login+failed:+{type(e).__name__}", status_code=status.HTTP_302_FOUND
|
url="/login?error=Social+login+failed.+Please+try+again.", status_code=status.HTTP_302_FOUND
|
||||||
)
|
)
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
@@ -6,8 +6,6 @@ import pytest
|
|||||||
from fastapi import Request, status
|
from fastapi import Request, status
|
||||||
from starlette.responses import RedirectResponse
|
from starlette.responses import RedirectResponse
|
||||||
|
|
||||||
_TEST_SECRET = "test-secret-value" # noqa: S105
|
|
||||||
|
|
||||||
|
|
||||||
@pytest.mark.unit
|
@pytest.mark.unit
|
||||||
class TestSocialProviders:
|
class TestSocialProviders:
|
||||||
@@ -311,6 +309,8 @@ class TestSocialCallback:
|
|||||||
|
|
||||||
assert isinstance(result, RedirectResponse)
|
assert isinstance(result, RedirectResponse)
|
||||||
assert "/login?error=Social+login+failed" in result.headers["location"]
|
assert "/login?error=Social+login+failed" in result.headers["location"]
|
||||||
|
# Ensure internal exception details are not exposed to the user
|
||||||
|
assert "Exception" not in result.headers["location"]
|
||||||
|
|
||||||
|
|
||||||
@pytest.mark.unit
|
@pytest.mark.unit
|
||||||
|
|||||||
Reference in New Issue
Block a user