fix(cloud): require CSRF state in the WorkOS login callback - #1886
Open
ra-co88 wants to merge 1 commit into
Open
fix(cloud): require CSRF state in the WorkOS login callback#1886ra-co88 wants to merge 1 commit into
ra-co88 wants to merge 1 commit into
Conversation
ra-co88
force-pushed
the
fix/login-csrf-state-mandatory
branch
from
August 30, 2026 17:12
6102fbd to
4a0c27e
Compare
Author
|
Heads-up on the red |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
The WorkOS login callback now requires a valid, unconsumed CSRF
stateparameter on every request. Missing state, unknown state, or a replayed (already consumed) state each return 400 before any WorkOS API call is made.Why
Login CSRF: an attacker can craft a callback URL that logs the victim into the attacker's account. The
stateparameter ties the callback to a login flow the user actually initiated — without enforcing it unconditionally, the callback accepts forged authorization codes. The check now happens before any network call to WorkOS, so forged requests are rejected at zero cost.What changed
state(400) before any WorkOS call.Breaking changes
Flows that initiate login server-side and construct the callback URL without a state parameter will now be rejected. If you drive login from a server, generate a random nonce, persist it server-side (or sign it), and pass it as
state— the callback validates it against the cookie it sets.Test plan
Focused suite on the callback handler (
apps/cloud/src/auth/workos-callback-state.node.test.ts):All green against current main.