Skip to content

fix(auth): Preserve browser consent bindings across concurrent OAuth approvals - #5541

Open
mikamikasuki wants to merge 1 commit into
PrefectHQ:mainfrom
mikamikasuki:fix/fmc-0017-consent-binding-cookie-race
Open

mikamikasuki wants to merge 1 commit into
PrefectHQ:mainfrom
mikamikasuki:fix/fmc-0017-consent-binding-cookie-race

Conversation

@mikamikasuki

Copy link
Copy Markdown
Contributor

Description

Use compact, independently signed browser-binding cookies per OAuth transaction, continue validating legacy shared cookies during their expiry window, and clear only the completed transaction's cookie.

Closes #5540

Contribution type

  • Bug fix (simple, well-scoped fix for a clearly broken behavior)
  • Documentation improvement
  • Enhancement

Checklist

  • This PR addresses an existing issue (or fixes a self-evident bug)
  • I have read CONTRIBUTING.md
  • I have added tests that cover my changes
  • I have run uv run prek run --all-files and all checks pass
  • I have self-reviewed my changes
  • If I used an LLM, it followed the repo's contributing conventions (not generic output)

Store each consent binding in its own compact signed cookie so concurrent approvals from the same browser snapshot do not overwrite one another. Preserve validation of legacy shared cookies during their expiry window and expire only the completed transaction binding.

🤖 Generated with OpenAI Codex
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

This pull request is awaiting maintainer assignment. Linked PRs stay open while maintainers triage the issue; this check remains failing until assignment.

Per CONTRIBUTING.md, an external PR must reference an issue that's assigned to its author. To get there:

  1. A maintainer will review the issue and decide whether to assign you. Please don't comment just to request assignment.

Once you're assigned and the link is present, this check is re-run automatically. Previously gate-closed PRs also reopen — no further action needed.

Maintainers: reopen this PR or remove the missing-issue-link label to bypass this check.

@marvin-context-protocol marvin-context-protocol Bot added auth Related to authentication (Bearer, JWT, OAuth, WorkOS) for client or server. bug Something isn't working. Reports of errors, unexpected behavior, or broken functionality. low-priority labels Oct 6, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

auth Related to authentication (Bearer, JWT, OAuth, WorkOS) for client or server. bug Something isn't working. Reports of errors, unexpected behavior, or broken functionality. low-priority missing-issue-link

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Concurrent OAuth consent approvals can overwrite the browser-binding cookie

1 participant