Skip to content

Support trusted provider emails and optional-email OAuth - #3

Merged
nedtwigg merged 2 commits into
mainfrom
easy-social-login
Sep 11, 2026
Merged

Support trusted provider emails and optional-email OAuth#3
nedtwigg merged 2 commits into
mainfrom
easy-social-login

Conversation

@nedtwigg

Copy link
Copy Markdown
Member

TTR now trusts Facebook’s returned email and should allow OAuth signup even when a provider does not share an email. Add opt-in trusted provider emails to bypass the local mailbox-code challenge, and optional-email accounts using Better Auth’s supported profile mapping. Public sessions expose email: null for these accounts; the reserved internal address cannot receive login codes.

Existing provider bindings and canonical emails remain stable. No schema migration or new dependency is required; conservative defaults remain available for other consumers.

Validation: all 146 tests pass, including same-email linking in both directions, single-session revocation, no-email signup/return, reserved-address rejection, and invalid OIDC assertions. Distributable packages verified in an independent installed consumer.

@nedtwigg
nedtwigg merged commit aa17e57 into main Sep 11, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant