fix: dedupe IdP auto-redirect and fix CSP/bfcache bug on the SPA shell

- Extract tryAutoRedirectToIdp() on the login page so onMount's redirect
  guard and the post-setup flow share one check instead of drifting.
- Fix a real bug: 304 Not Modified responses carry no Content-Type, so
  is_html misclassified them and attached the strict headerless CSP,
  which browsers merge into the cached 200's effective headers and
  defeat the SPA's hash-based CSP on revalidated repeat visits.
- Add Cache-Control: no-store on the SPA shell to opt out of bfcache,
  preventing a pre-deploy shell (stale inline hydration script + CSP
  hash) from being resurrected byte-for-byte across the OIDC redirect's
  full-page navigations.
- Add a manual, human-run SSO-only script/env (ports 8090/1081) since
  the automated oidc.hurl suite keeps password login enabled and never
  exercises the auto-redirect guard.
This commit is contained in:
M.Schmidt
2026-07-15 21:03:17 +02:00
parent 1acac1d699
commit 6215f37bf6
7 changed files with 328 additions and 11 deletions
+6 -1
View File
@@ -67,7 +67,12 @@ const configuration = {
{
client_id: 'oxicloud-test',
client_secret: 'test-client-secret-not-used-in-prod',
redirect_uris: ['http://localhost:8087/api/auth/oidc/callback'],
// 8087: automated tests/oidc/oidc.hurl suite. 8090: human-run
// tests/oidc/run-manual-sso-only.sh (SSO-only auto-redirect check).
redirect_uris: [
'http://localhost:8087/api/auth/oidc/callback',
'http://localhost:8090/api/auth/oidc/callback',
],
grant_types: ['authorization_code'],
response_types: ['code'],
token_endpoint_auth_method: 'client_secret_post',