T09 · Insecure Skill Coding Practices
- Location
src/qb/auth/oauth.py:15- Finding
OAuth authorization artifacts are routed through a hardcoded third-party ngrok endpoint
- Content
View full analysis
tuple[str, str]: """Generate authorization URL and state token. Returns: Tuple of (authorization_url, state_token) """ state = secrets.token_hex(16) params = { "client_id": client_id, "redirect_uri": REDIRECT_URI, "response_type": "code", "scope": SCOPES, "state": state, } url = f"{AUTHORIZATION_URL}?{urlencode(params)}" return url, state ``` It is also used during token exchange: ```python response = httpx.post( TOKEN_URL, headers={ "Authorization": _basic_auth_header(client_id, client_secret), "Content-Type": "application/x-www-form-urlencoded", "Accept": "application/json", }, data={ "grant_type": "authorization_code", "code": auth_code, "redirect_uri": REDIRECT_URI, }, timeout=30.0, ) ``` ### Technical Analysis The OAuth redirect URI determines where Intuit sends the authorization response. That response can contain a short-lived authorization code, the QuickBooks realm identifier, the OAuth state value, and error information. The implementation routes this response through a fixed ngrok hostname that is not an Intuit domain and is not shown as infrastructure controlled by t ...[truncated 2472 chars]- Remediation
View remediation
