google-auth
Audited by Socket on Sep 14, 2026
2 alerts found:
Anomalyx2The fragment is security guidance and integration sample code, not malicious package code. It contains no evident malware or supply-chain attack behavior. However, several examples have authentication weaknesses: optional or client-controlled nonce validation, inconsistent CSRF enforcement, and potentially unsafe automatic account linking by email. The server-issued, one-time nonce pattern should be used consistently, CSRF checks should fail closed where cookies are used for authentication, and account linking should require verified authoritative identity and preferably explicit confirmation.
The fragment implements a recognizable Google OAuth login flow and shows no clear malicious behavior. It has meaningful deployment security weaknesses: insecure OAuth transport is enabled, the session signing secret is hardcoded and weak, and HTTP localhost configuration is unsuitable for production. The credential store must be strongly protected because it contains access and refresh tokens. The assessment is limited to the displayed fragment and does not establish the security properties of credential_store or omitted code.