Skip to content

fix(integrations): remove injectable Outlook group lookup - #4217

Closed
kojiwakayama wants to merge 2 commits into
mainfrom
codex/propose-fix-for-odata-injection-vulnerability
Closed

kojiwakayama wants to merge 2 commits into
mainfrom
codex/propose-fix-for-odata-injection-vulnerability

Conversation

@kojiwakayama

Copy link
Copy Markdown
Contributor

Motivation

  • The Outlook find_group_by_mail tool inlined an untrusted mailAddress into a Microsoft Graph OData $filter, creating an OData injection primitive that could enumerate group IDs when combined with newly added group read scopes and group-thread tools.

Description

  • Removed the outlook__find_group_by_mail tool entry and its vulnerable https://graph.microsoft.com/v1.0/groups?$filter=mail eq '{mailAddress}' endpoint from the connector template cli/templates/integrations/outlook/connector.json and the generated data src/integrations/_data.ts.
  • Updated src/integrations/_data.test.ts to remove references to the unsafe tool and to add a regression assertion that the Outlook connector does not expose a outlook__find_group_by_mail tool.
  • Committed the changes as a focused fix that preserves existing group-thread/post tools which still require an explicit groupId.

Testing

  • Ran python3 -m json.tool cli/templates/integrations/outlook/connector.json to validate the JSON template and it succeeded.
  • Ran git diff --check and a Python presence scan to confirm the vulnerable find_group_by_mail identifier and the mail eq '{mailAddress}' template are absent from both the template and generated data, and those checks succeeded.
  • Attempted to run deno test --no-check --allow-all src/integrations/_data.test.ts but Deno is not available in the environment, so the repository unit tests were not executed here.

Codex Task

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for security reviews. Please try again later.

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.

@coderabbitai

coderabbitai Bot commented Aug 25, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 22 minutes.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: fad19cf6-5b70-4a05-a331-df3d99a177ec

📥 Commits

Reviewing files that changed from the base of the PR and between a2a3938 and b48d4f9.

📒 Files selected for processing (5)
  • docs/api-reference/veryfront/oauth.md
  • src/integrations/_data.test.ts
  • src/integrations/_data.ts
  • src/oauth/providers/microsoft.ts
  • templates/integrations/outlook/connector.json

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 35a86b1337

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/integrations/_data.test.ts

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e8eb4da082

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/oauth/providers/microsoft.ts
@kwakayama

kwakayama commented Aug 25, 2026 •

Copy link
Copy Markdown
Contributor

This patch is consolidated into #4224 at final SHA 1bfb35a. The rollup removes the injectable group lookup and the retained group tools/permissions so the reduced Outlook grant remains internally consistent. This PR will be closed as superseded after #4224 merges.

@kojiwakayama
kojiwakayama force-pushed the codex/propose-fix-for-odata-injection-vulnerability branch from e8eb4da to c8aa384 Compare August 25, 2026 17:36

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.

Squashed from:
- fix(integrations): remove injectable Outlook group lookup
- fix(integrations): drop Group.Read.All from Outlook scopes
@kojiwakayama
kojiwakayama force-pushed the codex/propose-fix-for-odata-injection-vulnerability branch from c8aa384 to c0264a7 Compare August 25, 2026 17:39

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.

@github-actions

Copy link
Copy Markdown

📦 Client bundle boundary

Entrypoint Modules Source size Server leaks
src/index.client.ts 330 1972 KiB ✅ 0

A server module in a client graph aborts hydration in the browser. New leaks fail CI; known leaks are tracked in scripts/lint/client-bundle-baseline.json to burn down.

@codecov

codecov Bot commented Aug 25, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@kojiwakayama

Copy link
Copy Markdown
Contributor Author

@codex review

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Keep it up!

Reviewed commit: b48d4f9e42

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@sonarqubecloud

Copy link
Copy Markdown

@kojiwakayama

Copy link
Copy Markdown
Contributor Author

Superseded by #4224, which consolidates this security hardening and is now merged at exact head 47e9834c65e71f9bed68204595626943bff349a2.

@kojiwakayama
kojiwakayama deleted the codex/propose-fix-for-odata-injection-vulnerability branch August 30, 2026 10:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants