Files
pad/internal/server
xarmian 10a55d1d5c feat(auth): accept provider=apple in cloud oauth-login/link/unlink (TASK-1773) (#714)
* feat(auth): accept provider=apple in cloud oauth-login/link/unlink (TASK-1773)

Sign in with Apple (PLAN-1772, App Store 4.8) needs pad to recognize
'apple' as an OAuth provider. The oauth-login, oauth-link, and
oauth-unlink handlers each hard-rejected anything but github/google;
DRY the triplicated literal into supportedOAuthProviders +
isSupportedOAuthProvider and add apple.

The rest of the path is already provider-agnostic: find-or-create user,
auto-link, the oauth_provider_not_linked gate for existing accounts, and
the verified-email requirement all work unchanged. Storage
(users.oauth_providers) is a free-form JSON array with no DB constraint,
so no migration.

Prerequisite for the pad-cloud /auth/apple/native endpoint (TASK-1774).

* test(auth): cover apple via oauth-link handler (Codex nit)

Prove the shared isSupportedOAuthProvider allowlist is wired through the
link call site, not only oauth-login. oauth-unlink shares the same gate
(unit-tested via TestIsSupportedOAuthProvider).
2026-06-07 22:08:14 -04:00
..