fix(auth): migrate e-mail-keyed storage only for a verified e-mail - #751
Merged
Merged
Conversation
The sign-in migration moved browser data saved under user:<e-mail> to the signed-in account's issuer+subject key whatever the token said about the address. On a shared browser, an account that only claims an address took the data saved under it, and the move is not a copy. Read email_verified from the token and move nothing unless it is true. Closes #750 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
yeongseon
approved these changes
Oct 5, 2026
yeongseon
left a comment
Collaborator
There was a problem hiding this comment.
diff 를 읽었고 CLEAN 이라 승인합니다. 리터럴 true 만 인정하고(없음·false·문자열 "true" 는 미검증), 실제 로그인 경로(initAuth → syncIdentity)에서 네 경우를 테스트합니다. 소유 키 자체는 그대로 두고 e-mail 키의 데이터를 가져오는 것만 막은 범위도 맞습니다.
이미 옮겨진 데이터는 되돌리지 않는다는 점은 본문대로 알아 두면 됩니다.
Open
2 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #750
문제
#740 (#731) 이 넣은 로그인 시 이전은
user:<e-mail>아래 저장된 브라우저 데이터를 로그인한 계정의sub:<issuer>#<subject>키로 옮기면서 그 e-mail 이 검증된 것인지 보지 않았다. 공용 브라우저에서 주소를 주장하기만 하는 계정이 그 주소 아래 저장된 것을 가져가고, 이전은 복사가 아니라 이동이라 되돌릴 수 없다. 제가 넣은 코드의 결함이다.변경
features/auth/store.ts:emailVerified: boolean. OIDC 세션에서만 참이 될 수 있고, mock 세션·로그아웃 상태는 거짓이다.features/auth/init.ts: 토큰의email_verified를 읽는다. 리터럴true만 인정한다 — 클레임이 없거나 문자열"true"이면 검증되지 않은 것으로 본다.features/auth/storageOwner.ts:migrateEmailOwnedStorage는emailVerified가 아니면 아무것도 옮기지 않는다.소유 키 자체(
resolveStorageOwnerKey)는 바꾸지 않았다. 미검증 계정도 자기sub:키 아래에 저장하고 읽는다 — 막는 것은 e-mail 키의 데이터를 가져오는 것뿐이다.테스트
__tests__/storageOwner.test.ts: 미검증 계정의 로그인은 아무것도 옮기지 않고 원래 항목이 그대로 남으며, 그 뒤 검증된 계정이 로그인하면 옮겨진다. 값을 주지 않은 identity 는 미검증이고clear()가 거짓으로 되돌린다.features/auth/init.test.ts: 실제 로그인 경로(initAuth→syncIdentity)에서email_verified가true/ 없음 /false/ 문자열"true"인 네 경우 — 첫 경우만 옮긴다.검증
npx vitest run __tests__/storageOwner.test.ts src/features/auth→Tests 64 passed (64).npx tsc --noEmit,npx eslint src/features/auth __tests__/storageOwner.test.ts출력 없음.알아 둘 것
emailscope 가 없어 access token 에email_verified가 실리지 않는 배포에서는 이전이 일어나지 않는다. 그런 배포는 Builder 도 토큰을 거절한다(docs/troubleshooting.md의email_verifiedPrecondition).🤖 Generated with Claude Code