Skip to content

Fix OAuth state check bypass (security)

Latest

Choose a tag to compare

@github-actions github-actions released this 27 Sep 12:44
Immutable release. Only release title and notes can be modified.

6.3.1 (2026-09-27)

This release fixes a security vulnerability. All users of @adonisjs/ally v6 should upgrade.

The OAuth2 and OAuth1 drivers accepted a callback with no state param (or no oauth_token param for OAuth1) when the state cookie was also missing. An attacker could use this to sign a victim in to the attacker's account, or to link the attacker's provider account to the victim's account. A missing state cookie now counts as a state mismatch, so stateMisMatch() returns true and accessToken() and user() throw E_OAUTH_STATE_MISMATCH.

See the security advisory for details: GHSA-j577-w94j-8p3p

Bug Fixes

  • treat a missing state cookie as a state mismatch (4126dc4)
  • add support for @adonisjs/inertia@5 peer dep (5c511d0)

Full Changelog: v6.3.0...v6.3.1