Skip to content

Block redirect-following and reject malformed auth responses across Node/Java/Go SDKs - #1

Merged
lbb00 merged 1 commit into
mainfrom
security/token-and-redirect-hardening
Aug 1, 2026
Merged

lbb00 merged 1 commit into
mainfrom
security/token-and-redirect-hardening

Conversation

@lbb00

@lbb00 lbb00 commented Aug 1, 2026

Copy link
Copy Markdown
Collaborator

Default HTTP clients no longer follow 3xx redirects (closing a path that could replay access-token/appSecret to an untrusted host), access tokens with unsafe header characters are rejected locally before any request, and auth endpoints reject malformed success responses (missing/empty accessToken, unparseable expiresAt) instead of silently caching a broken value.

Test plan

  • npm test (Node): 66/66 passing
  • ./gradlew test (Java): 86/86 passing
  • go test ./... (Go): 48/48 passing

…er characters, and reject malformed auth-token responses across Node/Java/Go SDKs

- Default HTTP clients (and any caller-injected client) no longer follow 3xx redirects, closing a path where a redirect could replay the access-token/appSecret to an untrusted host.
- Access tokens containing control characters are rejected locally before any request is sent (Node/Go); Java already had this check.
- Auth endpoints (client_credentials/code2Session/refreshToken) now reject success responses with a missing/empty accessToken or a malformed expiresAt instead of silently caching or returning a broken value.
- CI's generate-check workflow now runs on every push/PR instead of a path-filtered subset that didn't cover the generated directories it's meant to guard.
@lbb00
lbb00 merged commit f06fb05 into main Aug 1, 2026
4 checks passed
@lbb00
lbb00 deleted the security/token-and-redirect-hardening branch August 1, 2026 08:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant