Repository navigation
Stop the sign-in error page from showing text from the URL #411
Copy link
Copy link
Closed
Labels
AuthSecuritySecurity, access control, and data exposureSecurity, access control, and data exposurebugSomething isn't workingSomething isn't working
Milestone
Description
Activity
- added a parent issue
on Oct 6, 2026 - added a commit that references this issue
on Oct 6, 2026 - changed the title
[-]The sign-in error page shows attacker-written text from the URL[/-][+]Stop the sign-in error page from showing text from the URL[/+]on Oct 6, 2026 - addedSecuritySecurity, access control, and data exposureSecurity, access control, and data exposure
on Oct 6, 2026 Status: fixed in
c6fdc2donclaude/youthful-lovelace-3nvsc6. Not merged or deployed yet.What shipped:
apps/webapp/src/pages/auth/error.tsxnever renders text from the URL. Forotp_expiredit shows "This sign-in link has expired or was already used. Request a new link and try again." Every other code shows "Sign-in did not finish. Try again, or contact support if it keeps failing."apps/webapp/src/proxy.tsnow forwardserror_codeinstead oferror_description. The page needs the code to choose the expired-link message. The fix plan did not list this file.
Needs a maintainer decision: root
CLAUDE.md§Settled (Next product APIs) says "Do not editsrc/proxy.ts". The commit changes only the auth-error branch, and its message says approval is pending. If the edit is refused, revert only theproxy.tspart. The page then shows the general message for every error, so acceptance criterion 2 fails.Differences from the plan:
- No separate message for
access_denied. It gets the general message. - Step 3 (log the raw code and description) was optional and was not done.
Check after deploy:
/auth/error?error_description=Your%20account%20is%20lockedshows only fixed copy. An expired magic link shows the expired-link message.
Generated by Claude Code
- added 4 commits that reference this issue
on Oct 9, 2026
Metadata
Metadata
Assignees
Labels
AuthSecuritySecurity, access control, and data exposureSecurity, access control, and data exposurebugSomething isn't workingSomething isn't working
Summary
The auth error page prints
error_descriptionfrom the URL as-is. Anyone can send a link likehttps://docs.plus/?error=x&error_code=y&error_description=<text>and the victim sees that text in a red alert box on the real domain. React escapes it, so this is content spoofing, not XSS.apps/webappWhere
apps/webapp/src/proxy.ts:18-24forwards any?error=&error_code=request with itserror_descriptionto the error page.apps/webapp/src/pages/auth/error.tsx:11,36renders the text./auth/error?error_description=…link works too, without the proxy.Fix plan
apps/webapp/src/pages/auth/error.tsx, map known Supabaseerror_codevalues to fixed copy, for exampleotp_expired→ "This sign-in link has expired. Request a new one." andaccess_denied→ "Sign-in was cancelled."error_description.tech-writerskill (Simplified English).Acceptance criteria
/auth/error?error_description=Your%20account%20is%20lockedshows no attacker text.Generated by Claude Code