Files
calibre-web/cps
jvoisin 387678a771 Prevent OAuth relinking.
When an OAuth provider_user_id is already linked to User A, and User B
authenticates with the same OAuth identity, User B is silently logged in as
User A. This is by design for single-user OAuth, but in a multi-user
environment it means: if an attacker gains access to the same OAuth provider
account (e.g., a shared GitHub org account, or by compromising the OAuth
provider), they can log in as the linked Calibre-Web user with no password
needed.
2026-04-14 22:28:06 +02:00
..
2024-11-04 21:20:34 +01:00
2025-11-22 15:06:40 +01:00
2025-04-12 03:59:32 +08:00
2026-02-14 11:30:50 +01:00
2024-09-07 20:07:45 +02:00
2025-03-23 09:18:48 +01:00
2024-06-20 19:12:46 +02:00
2026-02-14 11:30:50 +01:00
2024-07-02 20:53:08 +02:00
2026-02-18 19:11:38 +01:00
2024-12-13 18:03:14 +01:00
2025-03-23 15:12:06 +01:00
2024-07-29 20:08:17 +02:00
2026-04-14 22:28:06 +02:00
2025-03-30 12:03:12 +02:00
2025-12-20 13:22:20 +01:00
2025-11-22 15:06:40 +01:00
2026-03-01 15:44:29 +01:00
2025-03-30 12:03:12 +02:00
2024-11-11 18:46:07 +01:00
2026-02-18 18:59:29 +01:00