feat(authentication): add OAuth sign-in-only mode - #1596
Merged
Merged
Conversation
2 tasks
cursor
Bot
force-pushed
the
cursor/oauth-signin-mode-af9f
branch
from
September 10, 2026 12:10
4a2bc05 to
e368e70
Compare
kkopanidis
marked this pull request as ready for review
September 10, 2026 12:49
ChrisPdgn
reviewed
Sep 15, 2026
ChrisPdgn
left a comment
Contributor
There was a problem hiding this comment.
Two product holes in mode=signIn. Default both is unchanged and non-breaking.
ChrisPdgn
approved these changes
Sep 15, 2026
ChrisPdgn
left a comment
Contributor
There was a problem hiding this comment.
Looks good — both review comments are addressed (invitationToken is treated as registration intent; web hooks redirect with conduitCode=REGISTRATION_NOT_ALLOWED).
Holding merge until the same fix lands on #1597 so 0.16.x matches this contract.
|
The same invite + web-hook redirect contract is on #1597 ( |
Allow OAuth init and token routes to request signIn or both (default). Sign-in-only blocks new user creation so clients can collect terms and profile data before registration. Co-authored-by: Konstantinos Kopanidis <kkopanidis@users.noreply.github.com>
Request mode remains a per-call UX switch. Provider allowRegistration (default true) is the policy ceiling so clients cannot force account creation when registration is disabled.
This reverts commit b94fe9a.
A present invitation token is registration intent, so mode=signIn no longer blocks invite signup. Web OAuth hooks send the browser back to the app with conduitCode=REGISTRATION_NOT_ALLOWED instead of 403 JSON.
kkopanidis
force-pushed
the
cursor/oauth-signin-mode-af9f
branch
from
September 15, 2026 11:47
3ba38e6 to
e76b289
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds a per-request OAuth
modeon login/register entry points so clients can start a flow as sign-in only or login and register.bothremains the default.This is a client-controlled UX switch (login screen vs register-after-terms). It is not a security boundary: anyone who can call the Client API can pass
mode=both. A config flag that disables OAuth registration entirely was considered and dropped, because that would block legitimate registration after extra steps.Type of change
API
modesignIn|bothbothwhen omittedApplied on:
GET /init/:providerandGET /initNative/:provider(stored on the OAuth state token)hookandPOST /native/:provider(read from state)POST /google,POST /facebookWhen
mode=signInand no matching user exists, the request fails withREGISTRATION_NOT_ALLOWED. Existing-user login, account linking, and invite signup (invitationToken) still work. Anonymous-user conversion is treated as registration and is blocked in sign-in-only mode.Web redirect hooks send the browser back to
customRedirectUri/ providerredirect_uriwithconduitCode=REGISTRATION_NOT_ALLOWED. Native token routes still return 403 JSON.How Has This Been Tested?
resolveOAuthMode,assertOAuthRegistrationAllowed(including invitation tokens), and redirect handling