fix: harden OAuth login flow — open redirect, path traversal, info leak

- Validate authorize_url is HTTPS before redirect (open redirect prevention)
- encodeURIComponent on provider name in API URL paths (path traversal prevention)
- encodeURIComponent on referralCode in t.me deep link
- Gate console.warn behind import.meta.env.DEV (no info leak in prod)
This commit is contained in:
Fringg
2026-02-11 02:58:04 +03:00
parent f74e316161
commit a744b41910
2 changed files with 17 additions and 5 deletions

View File

@@ -138,7 +138,7 @@ export const authApi = {
provider: string,
): Promise<{ authorize_url: string; state: string }> => {
const response = await apiClient.get<{ authorize_url: string; state: string }>(
`/cabinet/auth/oauth/${provider}/authorize`,
`/cabinet/auth/oauth/${encodeURIComponent(provider)}/authorize`,
);
return response.data;
},
@@ -146,7 +146,7 @@ export const authApi = {
// OAuth: callback (exchange code for tokens)
oauthCallback: async (provider: string, code: string, state: string): Promise<AuthResponse> => {
const response = await apiClient.post<AuthResponse>(
`/cabinet/auth/oauth/${provider}/callback`,
`/cabinet/auth/oauth/${encodeURIComponent(provider)}/callback`,
{ code, state },
);
return response.data;