Skip to content

fix(security): restore least-privilege Google Drive OAuth scopes - #4210

Closed
kojiwakayama wants to merge 2 commits into
mainfrom
codex/fix-drive-oauth-scope-vulnerability
Closed

kojiwakayama wants to merge 2 commits into
mainfrom
codex/fix-drive-oauth-scope-vulnerability

Conversation

@kojiwakayama

Copy link
Copy Markdown
Contributor

Motivation

  • A recent change expanded the Drive connector OAuth grant to https://www.googleapis.com/auth/drive, which grants full read/write/delete access across a user’s Drive and exposed destructive tools that accept caller-supplied fileId values.
  • This increases attacker impact where tools are reachable via agents or MCP surfaces, so the connector must use least-privilege scopes to limit mutation surface.

Description

  • Replaced the full Drive scope with the least-privilege combination https://www.googleapis.com/auth/drive.readonly and https://www.googleapis.com/auth/drive.file in the Drive connector metadata and generated client artifacts (cli/templates/integrations/drive/connector.json, cli/templates/integrations/drive/files/lib/drive-client.ts, and embedded cli/templates/manifest.json).
  • Updated the generated runtime integration catalog so the runtime src/integrations/_data.ts reflects the reduced scopes and updated consent-screen guidance.
  • Adjusted the setup guidance text to recommend drive.readonly and drive.file and clarified the drive.file app-file mutation boundary.
  • Added a regression assertion to src/integrations/_data.test.ts to assert the Drive connector requests the intended least-privilege scopes.

Testing

  • Ran git diff --check to validate no formatting or whitespace issues and it passed.
  • Executed a Python validation script that programmatically verified the connector JSON, the generated src/integrations/_data.ts, and the embedded template in cli/templates/manifest.json all now reference drive.readonly and drive.file, and the old auth/drive scope is absent, and the check succeeded.
  • Attempted to run the focused unit test with deno test --no-check --allow-all src/integrations/_data.test.ts but deno is not available in the execution environment, so the Deno test run could not be executed here (added a regression assertion nonetheless).

Codex Task

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for security reviews. Please try again later.

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.

@coderabbitai

coderabbitai Bot commented Aug 25, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 49 minutes.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 1d1618e8-d6b7-4872-b0ee-ebbc2e96a771

📥 Commits

Reviewing files that changed from the base of the PR and between a2a3938 and 5eda032.

⛔ Files ignored due to path filters (1)
  • templates/manifest.generated.ts is excluded by !**/*.generated.*
📒 Files selected for processing (7)
  • docs/api-reference/veryfront/oauth.md
  • src/integrations/_data.test.ts
  • src/integrations/_data.ts
  • src/oauth/providers/google.ts
  • templates/integrations/drive/connector.json
  • templates/integrations/drive/files/lib/drive-client.ts
  • templates/manifest.json

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 176ff407a8

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread templates/integrations/drive/connector.json

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 84316f876b

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/oauth/providers/google.ts
@github-actions

Copy link
Copy Markdown

📦 Client bundle boundary

Entrypoint Modules Source size Server leaks
src/index.client.ts 330 1972 KiB ✅ 0

A server module in a client graph aborts hydration in the browser. New leaks fail CI; known leaks are tracked in scripts/lint/client-bundle-baseline.json to burn down.

@kwakayama

kwakayama commented Aug 25, 2026 •

Copy link
Copy Markdown
Contributor

This patch is consolidated into #4224 at final SHA 1bfb35a. The rollup carries least-privilege Drive scopes and clears legacy full-scope stored tokens before use. This PR will be closed as superseded after #4224 merges.

@github-actions

Copy link
Copy Markdown

Thanks for your contribution, @claude!

Before we can merge this PR, we need you to accept our Contributor License Agreement (CLA).

Missing CLA entries for: @claude.

How to sign: Add contributor entry lines in CONTRIBUTORS.md in this PR:

Your Name (@claude)

By adding your name, you agree to the CLA. This is a one-time step.

If you are contributing on behalf of a company, please see our Corporate CLA.

@kojiwakayama
kojiwakayama force-pushed the codex/fix-drive-oauth-scope-vulnerability branch from 84316f8 to 8f0c692 Compare August 25, 2026 17:35

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.

Squashed from:
- fix(security): restore least-privilege Drive scopes
- fix(oauth): align Drive runtime defaultScopes with reduced connector scopes
@kojiwakayama
kojiwakayama force-pushed the codex/fix-drive-oauth-scope-vulnerability branch from 8f0c692 to c417568 Compare August 25, 2026 17:38

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.

@codecov

codecov Bot commented Aug 25, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@kojiwakayama

Copy link
Copy Markdown
Contributor Author

@codex review

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Nice work!

Reviewed commit: 5eda032be7

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@sonarqubecloud

Copy link
Copy Markdown

@kojiwakayama

Copy link
Copy Markdown
Contributor Author

Superseded by #4224, which consolidates this security hardening and is now merged at exact head 47e9834c65e71f9bed68204595626943bff349a2.

@kojiwakayama
kojiwakayama deleted the codex/fix-drive-oauth-scope-vulnerability branch August 30, 2026 10:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants