Files
pad/internal
xarmian 0657880d14 fix(auth): bind invitation acceptance to invitee email (TASK-650) (#177)
handleRegister and handleAcceptInvitation previously accepted any
authenticated/creatable account as the invitee. If an attacker learned
the invitation URL (email forwarding, shared screenshot, guessed code)
they could register a brand-new account at their own address and claim
the workspace seat, or sign into an existing account and attach the
invitation to it.

Add a case-insensitive strings.EqualFold check between the invitee
email (inv.Email) and:
- the signup form's Email field in handleRegister, before creating the
  account; and
- the authenticated user's Email in handleAcceptInvitation.

Mismatch returns 403 invitation_email_mismatch with a clear message
pointing the user at the intended address. EqualFold normalizes the
casing mismatch against the store's own ToLower() at create time.

Parent: PLAN-643 (OSS Security Hardening).
2026-04-21 20:20:19 -04:00
..
2026-03-26 01:52:36 +00:00
2026-03-26 01:52:36 +00:00