feat(auth): opt-in SSO domain verification — DNS-TXT proof + resultDialog UI (ADR-0024 ②)#2410
Merged
Conversation
…alog UI (ADR-0024 ②)
OS_SSO_DOMAIN_VERIFICATION (off by default) mounts @better-auth/sso's
/sso/{request-domain-verification,verify-domain} and enforces DNS domain
ownership before an external IdP may sign users in. Adds the request/verify
bridges (envelope-reshaped for the action resultDialog → ready-to-paste DNS TXT
record), the rawApp routes, and the sys_sso_provider domain_verified
field/column + Request/Verify actions.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Contributor
📓 Docs Drift CheckThis PR changes 2 package(s): 11 hand-written doc(s) reference the affected code and may need an implementation-accuracy re-verification:
|
…odeQL js/polynomial-redos) bareHostname's fallback used a regex on request-controlled input → high-sev ReDoS alert. Replace with indexOf-based truncation (URL() fast-path kept). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
xuyushun441-sys
pushed a commit
that referenced
this pull request
Jul 17, 2026
…ole coverage The previous revision under-covered the line in three ways, now fixed: 1. 15.0.0 was missing everything outside the ADR-0095 theme from the 14.8.0..15.0.0 range: the strict view/page schema BREAKING change (ADR-0089 D3a, #2943) with its migration, the per-row import automation chain + skipAutomations + runAutomations-default-ON behavior change (#2922), the sys_position/sys_capability system-row write guardrail (#2930), the bidirectional visibility lint (#2931), and the explain posture-label alignment (#2949). 2. 15.0.0 had NO Console section at all, despite bundling the objectui 14.0 major (13.2.0→14.0.0, ~73 commits — first release-page disclosure since much of it rode unversioned in the 14.8.0 pin): the ADR-0057 ChatDock consolidation (including its breaking cleanup #2475), the Gantt batch, lists/forms/auth/Studio/i18n enhancements, two security fixes (#2485/#2410), and the six early-14.1 commits the 15.0.0 pin picked up. 3. The 15.1.0 sections were over-compressed; every domain is now expanded to its full changeset detail, and the Console 14.1 section covers all eight areas of the 94-commit range instead of seven bullets. 465 → ~1000 lines; structure mirrors v14.mdx (per-minor annotations inside one major page, per docs/releases-maintenance.md). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
os-zhuang
added a commit
that referenced
this pull request
Jul 17, 2026
…ole coverage (#3082) * docs(releases): expand v15 page to full 14.8→15.0→15.1 backend + Console coverage The previous revision under-covered the line in three ways, now fixed: 1. 15.0.0 was missing everything outside the ADR-0095 theme from the 14.8.0..15.0.0 range: the strict view/page schema BREAKING change (ADR-0089 D3a, #2943) with its migration, the per-row import automation chain + skipAutomations + runAutomations-default-ON behavior change (#2922), the sys_position/sys_capability system-row write guardrail (#2930), the bidirectional visibility lint (#2931), and the explain posture-label alignment (#2949). 2. 15.0.0 had NO Console section at all, despite bundling the objectui 14.0 major (13.2.0→14.0.0, ~73 commits — first release-page disclosure since much of it rode unversioned in the 14.8.0 pin): the ADR-0057 ChatDock consolidation (including its breaking cleanup #2475), the Gantt batch, lists/forms/auth/Studio/i18n enhancements, two security fixes (#2485/#2410), and the six early-14.1 commits the 15.0.0 pin picked up. 3. The 15.1.0 sections were over-compressed; every domain is now expanded to its full changeset detail, and the Console 14.1 section covers all eight areas of the 94-commit range instead of seven bullets. 465 → ~1000 lines; structure mirrors v14.mdx (per-minor annotations inside one major page, per docs/releases-maintenance.md). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * docs(releases): note post-14.1 fixes carried by the final Console pin (#2615/#2617/#2619/#2620/#2621/#2623) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * docs(releases): add v15 to the releases index; mark v14 line final at 14.8.0 Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Jack Zhuang <277994282+os-zhuang@users.noreply.github.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Adds DNS-TXT domain-ownership verification for external SSO providers — the remaining ② item of the ADR-0024 Unified-Identity V1 plan (per-env external IdP). Gated behind a new
OS_SSO_DOMAIN_VERIFICATIONflag (off by default).When off (default): today's behavior is unchanged — register → login immediately.
When on:
@better-auth/ssomounts/sso/request-domain-verification+/sso/verify-domainand enforces a hard login gate — a provider whose email domain is not DNS-verified rejects logins (Provider domain has not been verified). These two are coupled in@better-auth/sso(the endpoints only register whendomainVerification.enabled), so one flag governs both. This prevents an org admin from registering a provider for a domain they don't control.Changes
auth-manager.ts— newssoDomainVerificationenabled-flag (readBooleanEnv, acceptstrue/1/yes/on) → passesdomainVerification: { enabled: true }tosso(); publicisSsoDomainVerificationEnabled()helper.register-sso-provider.ts—runRequestDomainVerification/runVerifyDomainbridges: re-dispatch through the gated better-auth endpoints (so the per-provider admin gate runs) and reshape the response into the{ success, data }envelope the actionresultDialogreads — request returns the ready-to-paste DNS TXT record ({ dnsRecordName, dnsRecordValue }); verify returns a clear success/error. A bare 404 from the inner endpoint is surfaced as "not enabled for this environment".auth-plugin.ts— mount the two bridges as rawApp routes (/admin/sso/{request-domain-verification,verify-domain}).sys_sso_provider—domain_verifiedfield + list column +Request Domain Verification/Verify Domainactions (request usesresultDialogto one-shot-reveal the DNS record);domainVerifieddocumented inAUTH_SSO_PROVIDER_SCHEMA.Verification (local prod-like stack,
OS_SSO_DOMAIN_VERIFICATION=true)request-domain-verification→ 200 with the exact DNS record (_better-auth-token-<id>.<domain>=_better-auth-token-<id>=<token>); rendered in the action's resultDialog (revealed values match byte-for-byte).verify-domain(no DNS) → 502 + friendly "DNS TXT record not found yet…".organizationIdset),domainVerified:false.sign-in/ssofor the unverified domain → 401Provider domain has not been verified.Domain Verifiedcolumn; both row actions appear.domain_verified:true) is inherently un-testable locally (needs a real domain + DNS TXT) — verified up to that boundary.The cloud env-runtime mount (
AuthProxyPlugin) +.framework-shabump land in a companion cloud PR.🤖 Generated with Claude Code