fix: avoid SQLite int overflow when matching numeric OAuth sub

Google subs are 21 digits, which is larger than SQLite's max INTEGER
(2**63-1), so binding int(sub) raises OverflowError and every login
fails. Only take the int comparison branch when the value actually
fits.
This commit is contained in:
osalloum 2026-08-26 10:47:08 +02:00
parent 56d296ef1b
commit b1bd37ad0e

View file

@ -366,7 +366,7 @@ class UsersTable:
sub_expr = User.oauth[provider]['sub'].as_string()
query = select(User).where(sub_expr == sub)
# SQLite preserves JSON numeric type here; Postgres ->> already compares numeric JSON as text.
if session.get_bind().dialect.name == 'sqlite' and sub.isdecimal():
if session.get_bind().dialect.name == 'sqlite' and sub.isdecimal() and int(sub) <= 2**63 - 1:
query = select(User).where(or_(sub_expr == sub, sub_expr == int(sub)))
row = (await session.execute(query)).scalars().first()
return UserModel.model_validate(row) if row else None