From 53819b173152945fa741a22a979c3d0e338924ab Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Wed, 27 Aug 2025 17:57:54 +0000 Subject: [PATCH] Fix OAuth state validation error by improving authentication configuration Co-authored-by: clayschaad <11883505+clayschaad@users.noreply.github.com> --- Server/Controllers/AuthController.cs | 27 +-------------------------- Server/Program.cs | 28 ++++++++++++++++++++++++++-- 2 files changed, 27 insertions(+), 28 deletions(-) diff --git a/Server/Controllers/AuthController.cs b/Server/Controllers/AuthController.cs index 3a08d03..7760dfe 100644 --- a/Server/Controllers/AuthController.cs +++ b/Server/Controllers/AuthController.cs @@ -23,35 +23,10 @@ namespace ShiftScheduler.Server.Controllers { return Challenge(new AuthenticationProperties { - RedirectUri = "/api/auth/callback" + RedirectUri = "/" }, GoogleDefaults.AuthenticationScheme); } - [HttpGet("callback")] - public async Task Callback() - { - // Explicitly specify the Google authentication scheme for the callback - var result = await HttpContext.AuthenticateAsync(GoogleDefaults.AuthenticationScheme); - if (!result.Succeeded || result.Principal == null) - { - return Redirect("/?error=auth_failed"); - } - - var emailClaim = result.Principal.FindFirst(ClaimTypes.Email) ?? - result.Principal.FindFirst("email"); - - if (emailClaim?.Value == null || !_authorizedEmails.Contains(emailClaim.Value)) - { - await HttpContext.SignOutAsync(); - return Redirect("/?error=unauthorized"); - } - - // Sign in with the cookie scheme after successful Google authentication - await HttpContext.SignInAsync(result.Principal); - - return Redirect("/"); - } - [HttpPost("logout")] [Authorize] public async Task Logout() diff --git a/Server/Program.cs b/Server/Program.cs index 173d706..7563ece 100644 --- a/Server/Program.cs +++ b/Server/Program.cs @@ -35,12 +35,36 @@ builder.Services.AddAuthentication(options => options.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme; options.DefaultChallengeScheme = GoogleDefaults.AuthenticationScheme; }) -.AddCookie() +.AddCookie(options => +{ + options.LoginPath = "/api/auth/login"; + options.LogoutPath = "/api/auth/logout"; + options.AccessDeniedPath = "/"; + options.ExpireTimeSpan = TimeSpan.FromDays(7); + options.SlidingExpiration = true; + options.Cookie.SameSite = SameSiteMode.Lax; + options.Cookie.SecurePolicy = CookieSecurePolicy.SameAsRequest; +}) .AddGoogle(googleOptions => { googleOptions.ClientId = builder.Configuration["Authentication:Google:ClientId"] ?? ""; googleOptions.ClientSecret = builder.Configuration["Authentication:Google:ClientSecret"] ?? ""; - googleOptions.CallbackPath = "/api/auth/callback"; + googleOptions.CallbackPath = "/signin-google"; + googleOptions.SaveTokens = true; + googleOptions.Events.OnTicketReceived = async context => + { + var emailClaim = context.Principal?.FindFirst(ClaimTypes.Email) ?? + context.Principal?.FindFirst("email"); + + if (emailClaim?.Value == null || !authorizedEmails.Contains(emailClaim.Value)) + { + context.Fail("Email not authorized"); + context.Response.Redirect("/?error=unauthorized"); + return; + } + + await Task.CompletedTask; + }; }); // Configure authorization policy for allowed emails