fix-backend-review-findings (ornith-35): oauth empty-token guard, session-secret startup assertion, OAuth email-link test
Fixes from ornith's backend code review, implemented by ornith-35 (cross-review by qwopus35b pending). 129/129 tests green.
This commit is contained in:
@@ -136,6 +136,9 @@ export async function exchangeCode(
|
||||
|
||||
const tokenJson = (await tokenRes.json()) as Record<string, unknown>;
|
||||
const accessToken = String(tokenJson.access_token ?? '');
|
||||
if (!accessToken) {
|
||||
throw new Error('Provider returned an empty access_token (likely an error response).');
|
||||
}
|
||||
|
||||
// Userinfo lookup
|
||||
const userinfoRes = await fetchFn(config.userinfoUrl, {
|
||||
|
||||
Reference in New Issue
Block a user