fix(security): restore least-privilege Google Drive OAuth scopes - #4210
kojiwakayama wants to merge 2 commits into
Conversation
|
You have reached your Codex usage limits for security reviews. Please try again later. |
There was a problem hiding this comment.
kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
|
Warning Review limit reachedNext included review available in 49 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Repository UI Review profile: CHILL Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (7)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 176ff407a8
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 84316f876b
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
📦 Client bundle boundary
A server module in a client graph aborts hydration in the browser. New leaks fail CI; known leaks are tracked in |
|
Thanks for your contribution, @claude! Before we can merge this PR, we need you to accept our Contributor License Agreement (CLA). Missing CLA entries for: @claude. How to sign: Add contributor entry lines in By adding your name, you agree to the CLA. This is a one-time step. If you are contributing on behalf of a company, please see our Corporate CLA. |
84316f8 to
8f0c692
Compare
There was a problem hiding this comment.
kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
Squashed from: - fix(security): restore least-privilege Drive scopes - fix(oauth): align Drive runtime defaultScopes with reduced connector scopes
8f0c692 to
c417568
Compare
There was a problem hiding this comment.
kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
|
@codex review |
There was a problem hiding this comment.
kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
|
Codex Review: Didn't find any major issues. Nice work! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
|
|
Superseded by #4224, which consolidates this security hardening and is now merged at exact head |



Motivation
https://www.googleapis.com/auth/drive, which grants full read/write/delete access across a user’s Drive and exposed destructive tools that accept caller-suppliedfileIdvalues.Description
https://www.googleapis.com/auth/drive.readonlyandhttps://www.googleapis.com/auth/drive.filein the Drive connector metadata and generated client artifacts (cli/templates/integrations/drive/connector.json,cli/templates/integrations/drive/files/lib/drive-client.ts, and embeddedcli/templates/manifest.json).src/integrations/_data.tsreflects the reduced scopes and updated consent-screen guidance.drive.readonlyanddrive.fileand clarified thedrive.fileapp-file mutation boundary.src/integrations/_data.test.tsto assert the Drive connector requests the intended least-privilege scopes.Testing
git diff --checkto validate no formatting or whitespace issues and it passed.src/integrations/_data.ts, and the embedded template incli/templates/manifest.jsonall now referencedrive.readonlyanddrive.file, and the oldauth/drivescope is absent, and the check succeeded.deno test --no-check --allow-all src/integrations/_data.test.tsbutdenois not available in the execution environment, so the Deno test run could not be executed here (added a regression assertion nonetheless).Codex Task