Skip to content

fix(oidc): accept numeric/boolean admin passwords from env vars (#8263) - #8327

Merged
JohnMcLear merged 2 commits into
developfrom
fix/8263-numeric-admin-password
Oct 11, 2026
Merged

JohnMcLear merged 2 commits into
developfrom
fix/8263-numeric-admin-password

Conversation

@JohnMcLear

Copy link
Copy Markdown
Member

Fixes #8263.

The settings loader coerces env values, so ADMIN_PASSWORD=123456 (e.g. via settings.json.docker) arrives as the number 123456. The OIDC interactive login check added in 3.3.6 (GHSA-62cj-9j72-mfrh) only accepted string passwords, so these admins could no longer log in. HTTP Basic already compared via toString().

  • verifyInteractiveLogin now accepts finite numbers and booleans (compared as strings); nullish, empty, NaN and non-scalar values are still refused.
  • Tests: unit cases for each type, plus an end-to-end test that runs a settings file with ${ADMIN_PASSWORD} through the real parseSettings loader.

🤖 Generated with Claude Code

https://claude.ai/code/session_012cFUmwE79DiLX4VsJqoTZV

JohnMcLear and others added 2 commits October 10, 2026 14:08
The settings loader coerces env-var values, so ADMIN_PASSWORD=123456 in
settings.json.docker arrives as the number 123456. The 3.3.6 OIDC login
check (GHSA-62cj-9j72-mfrh) only accepted string passwords, so such an
admin could no longer log in. HTTP Basic already compared via toString().
Accept finite numbers and booleans; still refuse nullish, empty, NaN and
non-scalar values.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WnNeNQpAJ5TWNZka4yugCw
@qodo-code-review

Copy link
Copy Markdown

ⓘ Qodo reviews are paused because the subscription is no longer active. Ask your workspace admin to reactivate the subscription to resume reviews. Manage billing

@qodo-free-for-open-source-projects

Copy link
Copy Markdown

PR Summary by Qodo

Restore OIDC login for coerced admin passwords

🐞 Bug fix 🧪 Tests 🕐 10-20 Minutes

Grey Divider

AI Description

• Accept numeric and boolean admin passwords produced by environment-variable substitution in OIDC
 interactive login.
• Preserve rejection of missing, empty, non-finite, and non-scalar stored passwords.
• Test direct comparisons and the real settings-loader path.
Diagram

graph TD
  Env["Admin environment variable"] --> Loader["Settings loader"] --> Users["User settings"] --> Interaction["OIDC interaction"] --> Verify{"Usable password?"} -->|match| Accept["Complete login"]
  Verify -->|invalid or mismatch| Reject["Reject login"]
Loading
High-Level Assessment

Keep the validation in the OIDC login check: it restores compatibility with settings-loader coercion without changing how other settings are parsed. Normalizing passwords in the shared loader would have a wider impact for this focused bug fix.

Files changed (2) +54 / -3

Bug fix (1) +9 / -3
OidcProviderSecurity.tsCompare usable scalar passwords in OIDC login +9/-3

Compare usable scalar passwords in OIDC login

• Accepts stored strings, booleans, and finite numbers by comparing their string values. Continues to refuse empty strings and unsupported stored values before the constant-time comparison.

src/node/security/OidcProviderSecurity.ts

Tests (1) +45 / -0
OidcProviderSecurity.tsCover coerced passwords and rejected values +45/-0

Cover coerced passwords and rejected values

• Adds direct checks for numeric and boolean passwords and rejection of objects, arrays, and NaN. Exercises environment-variable substitution through the real settings loader before checking interactive login.

src/tests/backend/specs/OidcProviderSecurity.ts

@qodo-free-for-open-source-projects

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)

Grey Divider

Great, no issues found!

Qodo reviewed your code and found no material issues that require review

Grey Divider

Tip of the day
💡 Did you know, you can tweak Display settings with a live preview to see your comment before it ships

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

@JohnMcLear
JohnMcLear merged commit 1902a25 into develop Oct 11, 2026
34 checks passed
@JohnMcLear
JohnMcLear deleted the fix/8263-numeric-admin-password branch October 11, 2026 13:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Admin user password doesn't work

1 participant