Address PR review feedback for OIDC login

- Remove sensitive nonce values from error messages to prevent logging leaks
- Guard ticker intervals against non-positive durations in SAML domain
  verifier and garbage collector to prevent panics
- Require both client ID and client secret for Google/Microsoft OIDC
  providers to be marked as enabled
- Replace http.DefaultClient with kit/httpclient for JWKS fetching to
  ensure proper timeouts
- Fix eslint indentation in SignInPage OIDC button click handler

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
This commit is contained in:
Bryan Frimin
2026-03-21 19:43:14 +01:00
parent 3066e7d14c
commit 29b41208f3
5 changed files with 31 additions and 20 deletions

View File

@@ -70,10 +70,10 @@ function OIDCButtons() {
onClick={() => {
window.location.href
= provider.loginURL
+ "?continue="
+ encodeURIComponent(
safeContinueUrl.pathname + safeContinueUrl.search,
);
+ "?continue="
+ encodeURIComponent(
safeContinueUrl.pathname + safeContinueUrl.search,
);
}}
>
<span className="flex items-center gap-2">