Skip to content

test: assert the userinfo claims in the OAuth flow - #88

Draft
mroderick wants to merge 2 commits into
mainfrom
test/userinfo-claims
Draft

mroderick wants to merge 2 commits into
mainfrom
test/userinfo-claims

Conversation

@mroderick

Copy link
Copy Markdown
Collaborator

The end-to-end OAuth flow test now asserts the userinfo response the planner resolves member identity from: sub matching the id_token sub, email, email_verified, and name. The flow requests the planner's scopes (openid profile email), which the test harness now allows like production src/auth.js does.

No production code changes: the deployed claim resolution already returns everything the planner needs. The test pins that contract so a userinfo regression fails CI.

Review notes

Focus on the userinfo assertions in Step 5. They run against better-auth 1.7.5 (the lockfile version), where the id_token is sparse and userinfo is the only source of the scope-gated claims. The name assertion sets a name over SQL first, because magic-link sign-up creates the user with an empty name and an empty name is the shape upstream better-auth#11193 crashes on.

Related: codebar/planner#2989, #83

Since better-auth 1.7 the id_token is sparse and the scope-gated claims live in the UserInfo
response. The end-to-end flow now requests the planner's scopes (openid profile email) and
asserts what the planner resolves identity from: the sub claim matching the id_token, plus
email, email_verified, and name.
@mroderick
mroderick force-pushed the test/userinfo-claims branch from e8e0c82 to 1a98095 Compare October 7, 2026 12:06

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant