Fix OAuth state check bypass (security)
·
35 commits
to 6.x
since this release
Immutable
release. Only release title and notes can be modified.
5.1.2 (2026-09-27)
This release fixes a security vulnerability. All users of @adonisjs/ally v5 should upgrade.
The OAuth2 and OAuth1 drivers accepted a callback with no state param (or no oauth_token param for OAuth1) when the state cookie was also missing. An attacker could use this to sign a victim in to the attacker's account, or to link the attacker's provider account to the victim's account. A missing state cookie now counts as a state mismatch, so stateMisMatch() returns true and accessToken() and user() throw E_OAUTH_STATE_MISMATCH.
See the security advisory for details: GHSA-j577-w94j-8p3p
- fix: treat a missing state cookie as a state mismatch (4684e3d)
Full Changelog: v5.1.1...v5.1.2