Skip to content

staging > master: one.gov.sg - #2399

Merged
jia1 merged 7 commits into
masterfrom
staging
Oct 9, 2026
Merged

jia1 merged 7 commits into
masterfrom
staging

Conversation

@jia1

@jia1 jia1 commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Original PR description in #2397. #2398 was to fix private key parsing that broke due to \n.

You may also refer to this beginner-friendly explainer of the 2 PRs: one.gov.sg Login Explained.html

pregnantboy and others added 3 commits October 7, 2026 09:19
Adds "Log in with one.gov.sg" alongside email OTP, replacing the
retired Singpass button. Uses authorization code + PKCE with
private_key_jwt client auth via openid-client.

- backend: /auth/one-gov-sg/login and /auth/one-gov-sg/callback,
  enabled only when ONE_GOV_SG_CLIENT_ID is set
- backend: single-use login transactions in Redis, bound to the
  browser with a strict httpOnly cookie
- backend: existing domain/manual whitelist gates access
- backend: redact callback params from request logs and Sentry
- backend: logout reports whether the session was a one.gov.sg login
- frontend: start/callback routes behind REACT_APP_ONE_GOV_SG_ENABLED
- frontend: callback params scrubbed from URL before telemetry starts
- frontend: spinner-only callback page, toast after one.gov.sg logout

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Deployed env vars carry the PEM with literal "\n", which
crypto.createPrivateKey rejects with DECODER routines::unsupported.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Deployed env vars carry the PEM with literal "\n", which
crypto.createPrivateKey rejects with DECODER routines::unsupported.

Co-authored-by: Ian Chen <ian@open.gov.sg>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
@jia1 jia1 self-assigned this Oct 7, 2026
* ci: run lint and test on PRs targeting staging

The default branch moved from master to staging, so feature PRs now
target staging. ci.yml only triggered on PRs to master, so those PRs
got no lint or test runs.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs: point README branch instructions at staging

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* chore: update secrets baseline line numbers for ci.yml

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
(cherry picked from commit 9039cd2f25839b6ab40491c261a7791c98a64ba4)
Co-authored-by: security-graft-app[bot] <237187419+security-graft-app[bot]@users.noreply.github.com>
@jia1
jia1 merged commit e809ea0 into master Oct 9, 2026
30 of 36 checks passed

This branch had an error being deployed

1 failed deployment
staging — 4f97ac3e Deployed Oct 8, 2026 by jia1 via End-to-end Test / playwright-run #998
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants