fix(integrations): remove injectable Outlook group lookup - #4217
kojiwakayama wants to merge 2 commits into
Conversation
|
You have reached your Codex usage limits for security reviews. Please try again later. |
There was a problem hiding this comment.
kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
|
Warning Review limit reachedNext included review available in 22 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Repository UI Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (5)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 35a86b1337
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: e8eb4da082
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
e8eb4da to
c8aa384
Compare
There was a problem hiding this comment.
kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
Squashed from: - fix(integrations): remove injectable Outlook group lookup - fix(integrations): drop Group.Read.All from Outlook scopes
c8aa384 to
c0264a7
Compare
There was a problem hiding this comment.
kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
📦 Client bundle boundary
A server module in a client graph aborts hydration in the browser. New leaks fail CI; known leaks are tracked in |
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
|
@codex review |
There was a problem hiding this comment.
kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
|
Codex Review: Didn't find any major issues. Keep it up! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
|
|
Superseded by #4224, which consolidates this security hardening and is now merged at exact head |



Motivation
find_group_by_mailtool inlined an untrustedmailAddressinto a Microsoft Graph OData$filter, creating an OData injection primitive that could enumerate group IDs when combined with newly added group read scopes and group-thread tools.Description
outlook__find_group_by_mailtool entry and its vulnerablehttps://graph.microsoft.com/v1.0/groups?$filter=mail eq '{mailAddress}'endpoint from the connector templatecli/templates/integrations/outlook/connector.jsonand the generated datasrc/integrations/_data.ts.src/integrations/_data.test.tsto remove references to the unsafe tool and to add a regression assertion that the Outlook connector does not expose aoutlook__find_group_by_mailtool.groupId.Testing
python3 -m json.tool cli/templates/integrations/outlook/connector.jsonto validate the JSON template and it succeeded.git diff --checkand a Python presence scan to confirm the vulnerablefind_group_by_mailidentifier and themail eq '{mailAddress}'template are absent from both the template and generated data, and those checks succeeded.deno test --no-check --allow-all src/integrations/_data.test.tsbut Deno is not available in the environment, so the repository unit tests were not executed here.Codex Task