fix(security): pin QuickBooks API origin - #4204
kojiwakayama wants to merge 3 commits into
Conversation
|
You have reached your Codex usage limits for security reviews. Please try again later. |
There was a problem hiding this comment.
kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
|
Warning Review limit reachedNext included review available in 33 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Repository UI Review profile: CHILL Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (7)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
|
Thanks for your contribution, @claude! Before we can merge this PR, we need you to accept our Contributor License Agreement (CLA). Missing CLA entries for: @claude. How to sign: Add contributor entry lines in By adding your name, you agree to the CLA. This is a one-time step. If you are contributing on behalf of a company, please see our Corporate CLA. |
📦 Client bundle boundary
A server module in a client graph aborts hydration in the browser. New leaks fail CI; known leaks are tracked in |
bb20d6d to
5a8eee9
Compare
There was a problem hiding this comment.
kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
Squashed from: - fix(security): pin QuickBooks API origin
5a8eee9 to
83eb996
Compare
There was a problem hiding this comment.
kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 83eb996723
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
|
@codex review |
There was a problem hiding this comment.
kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 9d8c75bb6d
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
|
@codex review |
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: de6210c863
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
|
||
| 1. Go to [Intuit Developer](https://developer.intuit.com/) | ||
| 2. Create app and get OAuth credentials | ||
| 2. Create or open an app with production access, then copy the production Client ID and Client Secret |
There was a problem hiding this comment.
Use an HTTPS callback with production credentials
When a user scaffolds QuickBooks and follows this newly production-only credential instruction, the next step still registers http://localhost:3000/api/auth/quickbooks/callback. Intuit production apps require an HTTPS redirect URI, while the HTTP localhost flow is intended for development credentials, so OAuth authorization is rejected before any request reaches the pinned production API. Update both scaffolded setup surfaces to specify the deployment's HTTPS callback URL or a secure local HTTPS tunnel, and cover that requirement in the setup contract test.
AGENTS.md reference: AGENTS.md:L13-L14
Useful? React with 👍 / 👎.
|
Superseded by #4224, which consolidates this security hardening and is now merged at exact head |



Motivation
{host}path parameter that allowed attacker-controlled URL authorities, risking OAuth access token exfiltration and SSRF; the intent of this change is to ensure QuickBooks requests always go to the official Intuit API origin.Description
cli/templates/integrations/quickbooks/connector.jsontohttps://quickbooks.api.intuit.comand remove the caller-controllablehostpath parameter.src/integrations/_data.tsreflects the pinned QuickBooks origins and no longer includes thehostparams.src/integrations/_data.test.tsthat asserts every QuickBooks endpointURLhas originhttps://quickbooks.api.intuit.comand that thehostparam is not present.Testing
python3 -m json.tool cli/templates/integrations/quickbooks/connector.jsonwhich succeeded.urlstarts withhttps://quickbooks.api.intuit.com/and that no tool exposes ahostparam, which succeeded.git diff --checkand repository status checks which reported no outstanding whitespace/format errors for the modified files.deno run -A scripts/build/generate-integrations-module.tsanddeno test ...), butdenois unavailable in the execution environment so those Deno steps could not be executed; the generatedsrc/integrations/_data.tswas updated and validated against the connector template using Python checks as a safe fallback.Codex Task