Skip to content

Require verified email for whitelisted-domain trust#5314

Merged
vitaliset merged 3 commits into
masterfrom
security/vuln1-oauth-email-verification-toctou
Jun 8, 2026
Merged

Require verified email for whitelisted-domain trust#5314
vitaliset merged 3 commits into
masterfrom
security/vuln1-oauth-email-verification-toctou

Conversation

@vitaliset

Copy link
Copy Markdown
Collaborator

Carry the real email_verified state on the User and require it before trusting an email's domain, closing the GitHub/EMU email-verification bypass. GitHub login and own-testcase access are unaffected.

b/516412711

Carry the real email_verified state on the User and require it before
trusting an email's domain, closing the GitHub/EMU email-verification
bypass. GitHub login and own-testcase access are unaffected.
@vitaliset vitaliset requested a review from a team as a code owner June 8, 2026 18:06
@vitaliset vitaliset requested a review from PauloVLB June 8, 2026 18:07
@vitaliset

Copy link
Copy Markdown
Collaborator Author

/gcbrun

@PauloVLB PauloVLB left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@vitaliset vitaliset enabled auto-merge (squash) June 8, 2026 19:08

@decoNR decoNR left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Rubberstamp since paulo's LGTM is not enough since he is not a member of clusterfuzz on github.

@vitaliset vitaliset merged commit e68fd25 into master Jun 8, 2026
13 of 14 checks passed
@vitaliset vitaliset deleted the security/vuln1-oauth-email-verification-toctou branch June 8, 2026 19:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants