Skip to content

test(verify): refuse the sign-in flow cookie presented as the session cookie - #252

Merged
Bccorb merged 1 commit into
mainfrom
test/guard-session-cookie-kind
Oct 8, 2026
Merged

Bccorb merged 1 commit into
mainfrom
test/guard-session-cookie-kind

Conversation

@Bccorb

@Bccorb Bccorb commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Follow-up to #251, which merged before this commit reached it.

Adds a conformance spec: the app's guard (GET /api/me) must answer 401 when the sign-in flow's ephemeral cookie is presented in the access cookie's place. Every adapter cookie can be signed with the same secret, and the ephemeral cookie is handed out before any factor is proven, so a guard that checks only the signature lets it pass for a session. That was fells-code/seamless-auth-server#211. verify/CONFORMANCE.md lists it under Guard.

Verified against the Express and Fastify reference apps built with fells-code/seamless-auth-server#211, and the Go reference app in fells-code/seamless-auth-go: 25 of 25 on each.

The daily released smoke test fails this spec until the release containing #211 is published, accurately: the currently published adapters accept that cookie.

… cookie

Every adapter cookie can be signed with the same secret, and the ephemeral
cookie is handed out before any factor is proven, so an adapter's guard must
not accept it in the access cookie's place. Express, Fastify and Go pass with
fells-code/seamless-auth-server#211.
@Bccorb
Bccorb merged commit 2882f80 into main Oct 8, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant