• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

go-pkgz / auth
86%
master: 85%

Build:
Build:
LAST BUILD BRANCH: refs/tags/v2.1.6
DEFAULT BRANCH: master
Repo Added 26 Dec 2018 08:17AM UTC
Files 25
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

LAST BUILD ON BRANCH refs/tags/v2.1.6
branch: SELECT
CHANGE BRANCH
x
  • No branch selected
  • allowed-provider-check
  • apple-reponse-mode-fix
  • aud-secrets
  • ava-factory
  • avatar-errnotfound
  • chore/go-fix
  • ci/go-1.26-golangci-2.12
  • configurable-microsoft-tenant
  • cookie-domain
  • custom-dev-host
  • custom-dev-port
  • dependabot/go_modules/_example/github.com/go-chi/chi/v5-5.2.2
  • dependabot/go_modules/_example/golang.org/x/crypto-0.17.0
  • dependabot/go_modules/_example/golang.org/x/image-0.38.0
  • dependabot/go_modules/_example/golang.org/x/image-0.5.0
  • dependabot/go_modules/_example/golang.org/x/net-0.17.0
  • dependabot/go_modules/_example/golang.org/x/net-0.7.0
  • dependabot/go_modules/golang.org/x/crypto-0.31.0
  • dependabot/go_modules/golang.org/x/image-0.38.0
  • dependabot/go_modules/golang.org/x/image-0.41.0
  • dependabot/go_modules/v2/github.com/golang-jwt/jwt/v5-5.2.2
  • dependabot/go_modules/v2/golang.org/x/crypto-0.31.0
  • dependabot/go_modules/v2/golang.org/x/crypto-0.45.0
  • dependabot/go_modules/v2/golang.org/x/crypto-0.52.0
  • dependabot/go_modules/v2/golang.org/x/image-0.41.0
  • dependabot/go_modules/v2/golang.org/x/net-0.33.0
  • dependabot/go_modules/v2/golang.org/x/net-0.36.0
  • direct-custom-id
  • docs/comment-sweep
  • dverhoturov/telegram_fix
  • email-sender
  • feat/csrf-middleware
  • feat/github-numeric-id
  • feature/custom-error-handler
  • fix-anon
  • fix-content-type-header
  • fix-oauth-from-open-redirect
  • fix-oauth-sendjwtheader
  • fix-providers-names
  • fix/admin-passwd-log-leak
  • fix/apple-id-token-iss-aud
  • fix/apple-log-redact-token-response
  • fix/auth-sensitive-logging
  • fix/avatar-content-type-spoofing-xss
  • fix/csp-consumer-note
  • fix/dev-custom-bind-localhost
  • fix/email-sender-redact-body
  • fix/panic-save-ava-nil
  • fix/telegram-redact-bot-token-in-avatar-url
  • fix/v1-from-redirect-validator
  • fix/verify-replay
  • fix/verify-replay-typed-nil-followup
  • followups/security-review
  • go1_20
  • jwt-header
  • master
  • microsoft
  • migrate-example-to-routegroup
  • no-ava
  • official-mongo-drvier
  • paskal/HttpOnly
  • paskal/add_common_processor
  • paskal/avatar_return_proper_content_type
  • paskal/bump_ci_go_version
  • paskal/bump_dep
  • paskal/bump_go_modules
  • paskal/bump_modules
  • paskal/double_close
  • paskal/email_module
  • paskal/facelift
  • paskal/fix_actions_test
  • paskal/fix_apple_key_panic
  • paskal/fix_custom_server
  • paskal/fix_error
  • paskal/fix_golangcilint
  • paskal/fix_lint_report
  • paskal/fix_send_jwt_header
  • paskal/google_auth_doc
  • paskal/improve_telegram
  • paskal/modules_bump
  • paskal/mongodb
  • paskal/moq
  • paskal/new_errors
  • paskal/plain_text
  • paskal/switch_to_v2
  • paskal/sync_v2
  • paskal/telegram_site_id
  • paskal/tg_username
  • paskal/token_generation_instructions
  • paskal/update-dependencies
  • paskal/update-modules
  • paskal/update_modules
  • paskal/update_pkcs8
  • paskal/v2
  • paskal/v2_golangcilint
  • paskal/v2_jwt5
  • ps/fix-example
  • rbac
  • refs/tags/v0.10.0
  • refs/tags/v0.10.1
  • refs/tags/v0.10.2
  • refs/tags/v0.11.0
  • refs/tags/v0.12.0
  • refs/tags/v0.12.1
  • refs/tags/v1.13.0
  • refs/tags/v1.13.1
  • refs/tags/v1.14.0
  • refs/tags/v1.15.0
  • refs/tags/v1.16.0
  • refs/tags/v1.17.0
  • refs/tags/v1.18.0
  • refs/tags/v1.19.0
  • refs/tags/v1.19.1
  • refs/tags/v1.20.0
  • refs/tags/v1.21.0
  • refs/tags/v1.22.0
  • refs/tags/v1.22.1
  • refs/tags/v1.23.0
  • refs/tags/v1.24.0
  • refs/tags/v1.24.1
  • refs/tags/v1.24.2
  • refs/tags/v1.25.1
  • refs/tags/v1.25.2
  • refs/tags/v1.25.3
  • refs/tags/v1.25.4
  • refs/tags/v1.25.5
  • refs/tags/v1.25.6
  • refs/tags/v1.5.1
  • refs/tags/v2.0.0
  • refs/tags/v2.1.0
  • refs/tags/v2.1.1
  • refs/tags/v2.1.2
  • refs/tags/v2.1.3
  • refs/tags/v2.1.4
  • refs/tags/v2.1.5
  • refs/tags/v2.1.6
  • remove-bluemonday
  • samesite
  • sanitize-verifyed
  • update-dependencies-2026-04
  • update-dependencies-dec2024
  • update-deps-and-golangci-v2
  • upgrade-repeater-v2
  • v0.8.0
  • v0.8.1
  • v0.8.2
  • v0.8.3
  • v0.9.0
  • verify-avatar

25 Jul 2026 01:08AM UTC coverage: 85.545% (+0.1%) from 85.445%
30137974767

push

github

web-flow
feat: opt-in github numeric user id, reject non-2xx user info (#301)

* feat: add opt-in github user id derived from immutable numeric id

GitHub logins are released on rename or account removal and can be claimed
by someone else, so a local id derived from the login may be inherited by
the next holder of the name. Every other oauth2 provider here keys on an
immutable subject, github was the only one on a mutable field.

Add Params.GithubNumericID and Service.AddGithubProviderWithNumericID to
derive the id from the numeric account id instead. Off by default because
it changes the id of every existing github user, and records stored under
the old id cannot be remapped offline once a login is hashed.

The numeric id is read from the raw response body with a typed unmarshal.
data.Value is not usable for it, json numbers decode to float64 and format
as "1.345027e+06". A missing or zero id keeps the login-based value rather
than hashing an empty string.

Applied to both the v1 (provider/) and v2 (v2/provider/) module paths.

* fix(review-loop): iteration 1 addressed 8 findings

- [major] [provider/providers.go:70] numeric ids shared a hash namespace with logins, which may be all-digit; domain-separate the hashed input with a "gid:" prefix
- [major] [auth_test.go] AddGithubProviderWithNumericID had no test; add Service-level coverage plus the default-unchanged negative case
- [minor] [provider/providers.go:69] warn when the numeric id is unusable instead of falling back silently
- [minor] [provider/providers.go:52] default the logger in NewGithub, the mapUser closure captures p before initOauth2Handler defaults its own copy
- [minor] [provider/providers.go:65] comment claimed the login fallback was safe; state the recycling caveat instead
- [minor] [provider/oauth2.go:62] document the best-effort fallback on Params.GithubNumericID and the Service method
- [minor] [auth.go:389] add the advanced-configuration note the AddMicrosoftProvider godoc carries
- [min... (continued)

37 of 41 new or added lines in 4 files covered. (90.24%)

3107 of 3632 relevant lines covered (85.55%)

8.6 hits per line

Relevant lines Covered
Build:
Build:
3632 RELEVANT LINES 3107 COVERED LINES
8.6 HITS PER LINE
Source Files on master
  • Tree
  • List 25
  • Changed 0
  • Source Changed 0
  • Coverage Changed 0
Coverage ∆ File Lines Relevant Covered Missed Hits/Line

Recent builds

Builds Branch Commit Type Ran Committer Via Coverage
30137974767 refs/tags/v2.1.6 feat: opt-in github numeric user id, reject non-2xx user info (#301) * feat: add opt-in github user id derived from immutable numeric id GitHub logins are released on rename or account removal and can be claimed by someone else, so a local id de... push 25 Jul 2026 01:12AM UTC web-flow github
85.55
30137971562 refs/tags/v1.25.6 feat: opt-in github numeric user id, reject non-2xx user info (#301) * feat: add opt-in github user id derived from immutable numeric id GitHub logins are released on rename or account removal and can be claimed by someone else, so a local id de... push 25 Jul 2026 01:12AM UTC web-flow github
85.49
30137974768 refs/tags/v2.1.6 feat: opt-in github numeric user id, reject non-2xx user info (#301) * feat: add opt-in github user id derived from immutable numeric id GitHub logins are released on rename or account removal and can be claimed by someone else, so a local id de... push 25 Jul 2026 01:12AM UTC web-flow github
85.49
30137971552 refs/tags/v1.25.6 feat: opt-in github numeric user id, reject non-2xx user info (#301) * feat: add opt-in github user id derived from immutable numeric id GitHub logins are released on rename or account removal and can be claimed by someone else, so a local id de... push 25 Jul 2026 01:12AM UTC web-flow github
85.55
30137880275 master feat: opt-in github numeric user id, reject non-2xx user info (#301) * feat: add opt-in github user id derived from immutable numeric id GitHub logins are released on rename or account removal and can be claimed by someone else, so a local id de... push 25 Jul 2026 01:11AM UTC web-flow github
85.49
30137880201 master feat: opt-in github numeric user id, reject non-2xx user info (#301) * feat: add opt-in github user id derived from immutable numeric id GitHub logins are released on rename or account removal and can be claimed by someone else, so a local id de... push 25 Jul 2026 01:11AM UTC web-flow github
85.55
30137641650 feat/github-numeric-id fix(test): drop shadowed variable in github provider subtest The "with extra scopes" subtest redeclared r inside the closure, shadowing the handler from the enclosing test. govet's shadow check is enabled and CI runs a pinned golangci-lint, so th... Pull #301 25 Jul 2026 01:04AM UTC umputun github
85.49
30137641644 feat/github-numeric-id fix(test): drop shadowed variable in github provider subtest The "with extra scopes" subtest redeclared r inside the closure, shadowing the handler from the enclosing test. govet's shadow check is enabled and CI runs a pinned golangci-lint, so th... Pull #301 25 Jul 2026 01:04AM UTC umputun github
85.55
29079091063 ci/go-1.26-golangci-2.12 ci: update checkout to v7 and codeql-action to v4, quote GITHUB_WORKSPACE Pull #300 10 Jul 2026 08:14AM UTC paskal github
85.51
29079091071 ci/go-1.26-golangci-2.12 ci: update checkout to v7 and codeql-action to v4, quote GITHUB_WORKSPACE Pull #300 10 Jul 2026 08:14AM UTC paskal github
85.45
See All Builds (1128)
  • Repo on GitHub
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc