zerobyte/app/server/lib/auth/middlewares/validate-sso-provider-id.ts
Nico 7a3932f969
feat: OIDC (#564)
* feat: oidc

feat: organization switcher

refactor: org context

feat: invitations

GLM

* feat: link current account

* refactor: own page for sso registration

* feat: per-user account management

* refactor: code style

* refactor: user existing check

* refactor: restrict provider configuration to super admins only

* refactor: cleanup / pr review

* chore: fix lint issues

* chore: pr feedbacks

* test(e2e): automated tests for OIDC

* fix: check url first for sso provider identification

* fix: prevent oidc provider to be named "credential"
2026-02-27 23:13:54 +01:00

25 lines
688 B
TypeScript

import { APIError } from "better-auth/api";
import type { AuthMiddlewareContext } from "~/server/lib/auth";
import { isReservedSsoProviderId } from "../utils/sso-provider-id";
export const validateSsoProviderId = async (ctx: AuthMiddlewareContext) => {
if (ctx.path !== "/sso/register") {
return;
}
if (!ctx.body || typeof ctx.body !== "object") {
return;
}
const providerId = (ctx.body as Record<string, unknown>).providerId;
if (typeof providerId !== "string") {
return;
}
if (isReservedSsoProviderId(providerId)) {
throw new APIError("BAD_REQUEST", {
message: `Invalid providerId. '${providerId}' is reserved and cannot be used for SSO providers.`,
});
}
};