Repository navigation
Conversation
Adds "Log in with one.gov.sg" alongside email OTP, replacing the retired Singpass button. Uses authorization code + PKCE with private_key_jwt client auth via openid-client. - backend: /auth/one-gov-sg/login and /auth/one-gov-sg/callback, enabled only when ONE_GOV_SG_CLIENT_ID is set - backend: single-use login transactions in Redis, bound to the browser with a strict httpOnly cookie - backend: existing domain/manual whitelist gates access - backend: redact callback params from request logs and Sentry - backend: logout reports whether the session was a one.gov.sg login - frontend: start/callback routes behind REACT_APP_ONE_GOV_SG_ENABLED - frontend: callback params scrubbed from URL before telemetry starts - frontend: spinner-only callback page, toast after one.gov.sg logout Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Deployed env vars carry the PEM with literal "\n", which crypto.createPrivateKey rejects with DECODER routines::unsupported. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Deployed env vars carry the PEM with literal "\n", which crypto.createPrivateKey rejects with DECODER routines::unsupported. Co-authored-by: Ian Chen <ian@open.gov.sg> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* ci: run lint and test on PRs targeting staging The default branch moved from master to staging, so feature PRs now target staging. ci.yml only triggered on PRs to master, so those PRs got no lint or test runs. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * docs: point README branch instructions at staging Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * chore: update secrets baseline line numbers for ci.yml Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
(cherry picked from commit 9039cd2f25839b6ab40491c261a7791c98a64ba4)
Co-authored-by: security-graft-app[bot] <237187419+security-graft-app[bot]@users.noreply.github.com>
seancze
approved these changes
Oct 9, 2026
This branch had an error being deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Original PR description in #2397. #2398 was to fix private key parsing that broke due to
\n.You may also refer to this beginner-friendly explainer of the 2 PRs: one.gov.sg Login Explained.html