Files
sim/apps
Waleed bf825126c6 fix(auth): let Microsoft sign-in link via Entra's domain-verified email claim (#6546)
* fix(auth): let Microsoft sign-in link via Entra's domain-verified email claim

Microsoft is excluded from accountLinking.trustedProviders because the email
claim is attacker-controllable on /common/ (nOAuth). Entra never emits
email_verified for work/school accounts, so Better Auth refused to link a
Microsoft identity onto any existing user row, permanently stranding those
users on account_not_linked.

Derive emailVerified from the xms_edov optional claim, which Entra emits only
when the email's domain belongs to the user's tenant and an admin verified it
— the one email signal a hostile tenant cannot forge. Microsoft stays
untrusted; the guard now passes on its own merits.

The mapper returns an empty object when unverified, so it can only ever
promote unverified to verified, never downgrade.

* chore(auth): drop the unused MICROSOFT_TENANT_ID knob

Hosted Sim serves many Entra tenants, so it must stay on the multi-tenant
endpoint — pinning is only meaningful for a self-hoster restricting sign-in to
their own directory, and nobody is asking for that yet. The xms_edov fix is
independent of the tenant setting, so this removes surface without touching
behavior.

* chore(auth): tighten the Microsoft linking comments
2026-08-11 11:41:50 -07:00
..