Skip to content

fix: guard against nil session in UserUpdate - #2666

Open
ridwanakf wants to merge 1 commit into
supabase:masterfrom
ridwanakf:fix/guard-nil-session-in-user-update
Open

fix: guard against nil session in UserUpdate#2666
ridwanakf wants to merge 1 commit into
supabase:masterfrom
ridwanakf:fix/guard-nil-session-in-user-update

Conversation

@ridwanakf

Copy link
Copy Markdown

What kind of change does this PR introduce?

Bug fix.

What is the current behavior?

Fixes #2665.

UserUpdate derefs session at lines 106 and 172 without checking it, so a token whose session_id claim is blank or the nil UUID panics the handler and you get a 500 back. The issue has the full trail of how Auth ends up issuing a token like that.

What is the new behavior?

Two session == nil || guards, so a missing session reads as "not good enough" rather than blowing up. Same thing requirePasskeyManagementAAL already does for the passkey endpoints. You get 401 insufficient_aal or 400 current_password_required instead of the 500.

One thing I want to call out, since the lazier fix looks identical from the outside: these have to fail closed, not open. If you skip the check when there's no session the panic also goes away, but then PUT /user comes back 200 with the password changed, no AAL2 and no current password. I tried it to be sure. That's why the tests assert the exact 401 and 400 instead of just "not a 500".

Tests are in user_test.go: a hook-issued token with a blanked session_id, the AAL2 line with a TOTP factor enrolled, and the current-password line. They panic on master and pass here.

Additional context

I left the token schema alone. Constraining what session_id can be set to is probably worth doing, but it'd change things for anyone whose hook already writes that claim, so it felt like its own PR rather than something to sneak in here.

Rest is green: vet, staticcheck, both gosec runs, and go test ./... -p 1 -race over all 36 packages with that one skipped.

@ridwanakf
ridwanakf requested a review from a team as a code owner August 1, 2026 05:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

PUT /user 500s when a customize_access_token hook blanks session_id

1 participant