next-auth icon indicating copy to clipboard operation
next-auth copied to clipboard

Opt-in for dangerous account linking

Open Gregoor opened this issue 3 years ago • 5 comments

Hi there, happy new year, it's me over from that thing.

I've decided to go down the road of using a next-auth fork internally as we trust our hand-selected set of auth providers to correctly verify email addresses. Now I am curious if you'd consider merging it into upstream as well.

If so, I'd be happy to add docs, tests or whatever else you think is needed for this to be mergeable. Naming is another thing I've been wondering about. Maybe the flag should be called dangerouslyTrustAccountEmail instead? Or something else?

Reasoning 💡

By default account linking can only be done through an active session, to prevent account stealing from low-trust providers. Some next-auth users might trust their chosen providers enough to opt them into more lax account linking.

Checklist 🧢

  • [ ] Documentation
  • [ ] Tests
  • [ ] Ready to be merged

Thanks for the consideration (and the great work on next-auth!)

Gregoor avatar Jan 03 '22 13:01 Gregoor

Hi and thanks!

Making it opt-in might be an acceptable solution. I'll try to take this up with the others.

I'll cc @iaincollins, he might have an opinion as well.

balazsorban44 avatar Jan 03 '22 14:01 balazsorban44

It looks like this issue did not receive any activity for 60 days. It will be closed in 7 days if no further activity occurs. If you think your issue is still relevant, commenting will keep it open. Thanks!

stale[bot] avatar Mar 29 '22 01:03 stale[bot]

Any updates on this?

ferrohd avatar Mar 29 '22 12:03 ferrohd

It looks like this issue did not receive any activity for 60 days. It will be closed in 7 days if no further activity occurs. If you think your issue is still relevant, commenting will keep it open. Thanks!

stale[bot] avatar May 30 '22 22:05 stale[bot]

Hi, any updates on this? It would really help with a project I'm working on. Let me know if I can be of any help!

wedfgh avatar May 31 '22 16:05 wedfgh

Superseded by https://github.com/nextauthjs/next-auth/pull/5513

balazsorban44 avatar Oct 09 '22 22:10 balazsorban44