Skip to content

[MEDIUM] OAuth callback input not validated #223

@ibuyspy

Description

@ibuyspy

Unvalidated query boundary in \�pps/api/src/modules/auth/router.ts:40-44. Missing state/PKCE checks.

Fix: Zod-validate callback query; enforce OAuth state and PKCE verification.
Source: Security audit

Metadata

Metadata

Assignees

No one assigned

    Labels

    securitySecurity-related finding

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions