fix(mock-oauth2-provider): resolve CodeQL prototype pollution and open redirect - #11810
Open
raymondfeng wants to merge 3 commits into
Open
raymondfeng wants to merge 3 commits into
raymondfeng wants to merge 3 commits into
Conversation
…n redirect Registered apps and issued tokens were held in plain objects keyed by values taken from the request, so a `__proto__` key reached `Object.prototype`. They are `Map`s now, which also drops the `[key: string]: any` index signature from the `App` interface (CodeQL js/prototype-polluting-assignment). `redirect_uri` is validated before a token is issued and the callback url is built from the parsed `URL` rather than by concatenating the request value. A real authorization server matches `redirect_uri` against the callback urls registered for the client; this provider only ever serves test applications running on the same machine, so it accepts loopback hosts (CodeQL js/server-side-unvalidated-url-redirection). The async route handlers are wrapped so that rejections reach Express instead of becoming unhandled promise rejections. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: Raymond Feng <enjoyjava@gmail.com>
6 of 8 tasks
The US Census geocoder now returns slightly different coordinates for the test address, so `GeoLookupService` and `TodoApplication` tests fail on every platform, on master as well. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: Raymond Feng <enjoyjava@gmail.com>
The hook that launches puppeteer and loads the page intermittently exceeds 15 seconds on the ubuntu-latest runners. It now gets 30 seconds, the same as the hook that generates the bundle. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: Raymond Feng <enjoyjava@gmail.com>
4 of 8 tasks
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Resolves two CodeQL findings in the
mock-oauth2-providertest fixture. Split out of #11793.__proto__key reachedObject.prototype. They areMaps now.redirect_uriis parsed and restricted to loopback hosts, since this provider only serves test applications on the same machine. It is validated before a token is issued, so a rejected (400) request no longer leaves a token behind.The async route handlers are also wrapped so that rejections reach Express instead of becoming unhandled promise rejections. #11793 needs this, because
no-misused-promisesreports these handlers under TypeScript 6.Checklist
npm testpasses on your machine: the fixture compiles and lints clean, and the full suite was run on feat(build)!: compile with the TypeScript 7 native compiler #11793, which includes this commitpackages/cliwere updatedexamples/*were updated🤖 Generated with Claude Code