mirror of
https://github.com/tiennm99/DocsGPT.git
synced 2026-10-03 20:12:55 +00:00
The connector OAuth popup posted the session token to window.opener with a '*' target origin, so any page that opened the popup received it. An attacker with an account on a multi-user deployment could start a flow for their own pending session, get a victim to finish the provider consent, and receive a token backed by the victim's Drive/SharePoint/Confluence tokens. - Post popup results only to allowed frontend origins: the callback origin, OIDC_FRONTEND_URL, the new CONNECTOR_ALLOWED_ORIGINS, and localhost:5173 when the callback runs on a loopback host. - Render the success page from the callback itself so the token never appears in a URL; callback-status ignores session_token/user_email params. - ConnectorAuth accepts messages only from the popup it opened, on the callback origin reported by /api/connectors/auth. - /api/connectors/disconnect requires auth and only deletes the caller's session. - /api/connectors/sync and /api/remote reject session tokens the caller does not own. Fixes #2766