Skip to content

OAuth: Fix Broken Access Control - #149

Open
n7studios wants to merge 4 commits into
tests-fix-accept-popupsfrom
fix-oauth-broken-access-control
Open

n7studios wants to merge 4 commits into
tests-fix-accept-popupsfrom
fix-oauth-broken-access-control

Conversation

@n7studios

@n7studios n7studios commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Validates OAuth authorization requests before exchanging the authorization code for an access token:

  • The user must be logged in with the manage_options capability.
  • The request must include a valid nonce, which proves the same user started the Connect flow.

Kit's OAuth redirect only keeps the page, tab and section parameters from the return URL. page must stay convertkit-mm, so the nonce is sent and returned in tab (tab=convertkit-mm-oauth-{nonce}). After a successful exchange, the Plugin redirects back to the standard settings screen.

maybe_disconnect() now also checks for the manage_options capability.

Testing

  • testAuthorizationCodeNotExchangedWhenUnauthenticated: confirms no authorization code is exchanged, and credentials stay unchanged, for requests from logged-out users.
  • testAuthorizationCodeNotExchangedWithoutNonce: confirms the same when an Administrator's request has a missing or invalid nonce.
  • testNoCredentials: updated to decode the OAuth state parameter and check the return URL includes the nonce.
  • Checked manually: connecting to Kit through OAuth still works.

Checklist

@n7studios n7studios self-assigned this Sep 30, 2026
@n7studios n7studios added the bug label Sep 30, 2026
@n7studios
n7studios changed the base branch from main to tests-fix-accept-popups September 30, 2026 14:54
@n7studios
n7studios marked this pull request as ready for review September 30, 2026 15:51
@n7studios
n7studios requested review from a team, ciccio-kit and noelherrick and removed request for a team September 30, 2026 15:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

1 participant