Skip to content

fix(security): pin QuickBooks API origin - #4204

Closed
kojiwakayama wants to merge 3 commits into
mainfrom
codex/fix-quickbooks-oauth-token-exfiltration-vulnerability
Closed

kojiwakayama wants to merge 3 commits into
mainfrom
codex/fix-quickbooks-oauth-token-exfiltration-vulnerability

Conversation

@kojiwakayama

Copy link
Copy Markdown
Contributor

Motivation

  • A QuickBooks connector template exposed a caller-controlled {host} path parameter that allowed attacker-controlled URL authorities, risking OAuth access token exfiltration and SSRF; the intent of this change is to ensure QuickBooks requests always go to the official Intuit API origin.

Description

  • Pin all QuickBooks tool endpoints in cli/templates/integrations/quickbooks/connector.json to https://quickbooks.api.intuit.com and remove the caller-controllable host path parameter.
  • Regenerate / update the runtime integration catalog so src/integrations/_data.ts reflects the pinned QuickBooks origins and no longer includes the host params.
  • Update QuickBooks setup guidance in the template to require production credentials and remove sandbox-host guidance that could encourage changing the origin.
  • Add a regression test src/integrations/_data.test.ts that asserts every QuickBooks endpoint URL has origin https://quickbooks.api.intuit.com and that the host param is not present.

Testing

  • Ran JSON validation on the edited connector template with python3 -m json.tool cli/templates/integrations/quickbooks/connector.json which succeeded.
  • Ran a custom Python validation script that iterated the 13 QuickBooks tools and asserted every endpoint url starts with https://quickbooks.api.intuit.com/ and that no tool exposes a host param, which succeeded.
  • Ran git diff --check and repository status checks which reported no outstanding whitespace/format errors for the modified files.
  • Attempted the repository generation and test commands that normally run under Deno (deno run -A scripts/build/generate-integrations-module.ts and deno test ...), but deno is unavailable in the execution environment so those Deno steps could not be executed; the generated src/integrations/_data.ts was updated and validated against the connector template using Python checks as a safe fallback.

Codex Task

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for security reviews. Please try again later.

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.

@coderabbitai

coderabbitai Bot commented Aug 25, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 33 minutes.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 6fe05361-d8a3-4114-bcee-0947d3d8d949

📥 Commits

Reviewing files that changed from the base of the PR and between a2a3938 and de6210c.

⛔ Files ignored due to path filters (1)
  • templates/manifest.generated.ts is excluded by !**/*.generated.*
📒 Files selected for processing (7)
  • src/integrations/_data.test.ts
  • src/integrations/_data.ts
  • src/oauth/providers/common.test.ts
  • templates/integrations/_base/files/SETUP.md
  • templates/integrations/_base/files/app/setup/page-helpers.tsx
  • templates/integrations/quickbooks/connector.json
  • templates/manifest.json

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.

@github-actions

Copy link
Copy Markdown

Thanks for your contribution, @claude!

Before we can merge this PR, we need you to accept our Contributor License Agreement (CLA).

Missing CLA entries for: @claude.

How to sign: Add contributor entry lines in CONTRIBUTORS.md in this PR:

Your Name (@claude)

By adding your name, you agree to the CLA. This is a one-time step.

If you are contributing on behalf of a company, please see our Corporate CLA.

@github-actions

github-actions Bot commented Aug 25, 2026 •

Copy link
Copy Markdown

📦 Client bundle boundary

Entrypoint Modules Source size Server leaks
src/index.client.ts 330 1973 KiB ✅ 0

A server module in a client graph aborts hydration in the browser. New leaks fail CI; known leaks are tracked in scripts/lint/client-bundle-baseline.json to burn down.

@kwakayama

kwakayama commented Aug 25, 2026 •

Copy link
Copy Markdown
Contributor

This patch is consolidated into #4224 at final SHA 1bfb35a. The rollup carries the fixed QuickBooks origin and regression coverage. This PR will be closed as superseded after #4224 merges.

@kojiwakayama
kojiwakayama force-pushed the codex/fix-quickbooks-oauth-token-exfiltration-vulnerability branch from bb20d6d to 5a8eee9 Compare August 25, 2026 17:35

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.

Squashed from:
- fix(security): pin QuickBooks API origin
@kojiwakayama
kojiwakayama force-pushed the codex/fix-quickbooks-oauth-token-exfiltration-vulnerability branch from 5a8eee9 to 83eb996 Compare August 25, 2026 17:38

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 83eb996723

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread templates/integrations/quickbooks/connector.json
@codecov

codecov Bot commented Aug 25, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@kojiwakayama

Copy link
Copy Markdown
Contributor Author

@codex review

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 9d8c75bb6d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread templates/integrations/quickbooks/connector.json

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.

@kojiwakayama

Copy link
Copy Markdown
Contributor Author

@codex review

@sonarqubecloud

Copy link
Copy Markdown

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: de6210c863

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".


1. Go to [Intuit Developer](https://developer.intuit.com/)
2. Create app and get OAuth credentials
2. Create or open an app with production access, then copy the production Client ID and Client Secret

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Use an HTTPS callback with production credentials

When a user scaffolds QuickBooks and follows this newly production-only credential instruction, the next step still registers http://localhost:3000/api/auth/quickbooks/callback. Intuit production apps require an HTTPS redirect URI, while the HTTP localhost flow is intended for development credentials, so OAuth authorization is rejected before any request reaches the pinned production API. Update both scaffolded setup surfaces to specify the deployment's HTTPS callback URL or a secure local HTTPS tunnel, and cover that requirement in the setup contract test.

AGENTS.md reference: AGENTS.md:L13-L14

Useful? React with 👍 / 👎.

@kojiwakayama

Copy link
Copy Markdown
Contributor Author

Superseded by #4224, which consolidates this security hardening and is now merged at exact head 47e9834c65e71f9bed68204595626943bff349a2.

@kojiwakayama
kojiwakayama deleted the codex/fix-quickbooks-oauth-token-exfiltration-vulnerability branch August 30, 2026 10:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants