fix-backend-review-findings (ornith-35): oauth empty-token guard, session-secret startup assertion, OAuth email-link test

Fixes from ornith's backend code review, implemented by ornith-35 (cross-review by
qwopus35b pending). 129/129 tests green.
This commit is contained in:
Investor Flow Build
2026-06-29 23:33:02 -04:00
parent a303720c35
commit 2c7e7a0786
6 changed files with 526 additions and 0 deletions
+3
View File
@@ -136,6 +136,9 @@ export async function exchangeCode(
const tokenJson = (await tokenRes.json()) as Record<string, unknown>;
const accessToken = String(tokenJson.access_token ?? '');
if (!accessToken) {
throw new Error('Provider returned an empty access_token (likely an error response).');
}
// Userinfo lookup
const userinfoRes = await fetchFn(config.userinfoUrl, {