nextjs-authentication
Warn
Audited by Socket on Sep 14, 2026
1 alert found:
AnomalyAnomalyreferences/oauth-providers.md
LOWAnomalyLOW
references/oauth-providers.md
The fragment is legitimate OAuth/Auth.js documentation and contains no evidence of malware or supply-chain sabotage. It has notable configuration risks: dangerous email-based account linking, broad Google permissions, permissive sign-in validation, and storage of bearer tokens in JWT state. These are application security concerns rather than malicious behavior and should be reviewed before production use.
Confidence: 98%Severity: 58%
Audit Metadata