chore(web): guard OAuth API routes against 307/308 redirects - #1163

Merged
brendan-kellam merged 2 commits into
mainfrom
brendan/oauth-307-redirect-guard-SOU-945
Apr 30, 2026
Merged

chore(web): guard OAuth API routes against 307/308 redirects#1163
brendan-kellam merged 2 commits into
mainfrom
brendan/oauth-307-redirect-guard-SOU-945

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Apr 30, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-945

Summary

  • Adds packages/web/src/ee/features/oauth/apiHandler.ts — a thin wrapper around apiHandler that throws if the wrapped handler ever returns HTTP 307 or 308. Per RFC 9700 §4.12, the OAuth authorization server must not use 307/308 on redirects carrying user credentials, since those statuses preserve the request method and body. The error message cites the spec.
  • Swaps apiHandleroauthApiHandler in every authorization-server route handler:
    • app/api/(server)/ee/oauth/token/route.ts
    • app/api/(server)/ee/oauth/register/route.ts
    • app/api/(server)/ee/oauth/revoke/route.ts
    • app/api/(server)/ee/.well-known/oauth-authorization-server/route.ts (RFC 8414)
    • app/api/(server)/ee/.well-known/oauth-protected-resource/[...path]/route.ts (RFC 9728)
  • Adds unit tests for the wrapper covering pass-through (200/302/303/400) and rejection (307/308) cases.

This is defense-in-depth on top of the existing posture: no authorization-server endpoint emits 307 or 308 today, but this wrapper makes regressions fail at request time rather than ship silently.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features

    • OAuth authorization-server routes now reject HTTP 307 and 308 responses at runtime.
  • Tests

    • Added test coverage for OAuth handler validation of HTTP redirect statuses.

Adds `oauthApiHandler`, a thin wrapper around `apiHandler` that throws
if the wrapped handler ever returns an HTTP 307 or 308 response. Per
RFC 9700 §4.12, an OAuth authorization server must not use 307/308 on
redirects that could carry user credentials, since those status codes
preserve the request method and body.
Wires `oauthApiHandler` into all five authorization-server route
handlers — the token, register, and revoke endpoints under
`/api/ee/oauth/*`, plus the two RFC 8414 / RFC 9728 discovery endpoints
under `/api/ee/.well-known/*` — so any future change that accidentally
introduces a 307/308 from these routes throws at request time rather
than silently shipping.
Includes unit tests verifying the wrapper passes through 200/302/303/400
responses unchanged and throws on 307 and 308.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Apr 30, 2026

Copy link
Copy Markdown
Contributor

Walkthrough

This PR introduces a runtime guard for OAuth authorization-server route handlers that rejects HTTP 307 and 308 redirect responses in accordance with RFC 9700 §4.12. A new oauthApiHandler wrapper is implemented and applied across five OAuth endpoint routes.

Changes

Cohort / File(s)Summary
Documentation
CHANGELOG.md
Added "Changed" entry documenting the runtime guard for HTTP 307/308 response rejection on OAuth routes.
OAuth Route Handlers
packages/web/src/app/api/(server)/ee/.well-known/oauth-authorization-server/route.ts, packages/web/src/app/api/(server)/ee/.well-known/oauth-protected-resource/[...path]/route.ts, packages/web/src/app/api/(server)/ee/oauth/register/route.ts, packages/web/src/app/api/(server)/ee/oauth/revoke/route.ts, packages/web/src/app/api/(server)/ee/oauth/token/route.ts
Replaced apiHandler wrapper with oauthApiHandler on all exported route handlers; internal logic and request validation remain unchanged.
OAuth Handler Implementation
packages/web/src/ee/features/oauth/apiHandler.ts
New oauthApiHandler wrapper function that delegates to apiHandler and throws an error if the wrapped handler returns HTTP 307 or 308 status codes, otherwise returns the response unmodified.
Handler Tests
packages/web/src/ee/features/oauth/apiHandler.test.ts
New test suite verifying oauthApiHandler preserves status codes for 200, 302, 303, and 400 responses, and throws an RFC 9700-referencing error when encountering 307 or 308 responses.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~12 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title 'chore(web): guard OAuth API routes against 307/308 redirects' accurately and specifically describes the main change: implementing a runtime guard against HTTP 307/308 responses in OAuth routes.
Docstring Coverage✅ PassedDocstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/oauth-307-redirect-guard-SOU-945

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share
Review rate limit: 6/8 reviews remaining, refill in 14 minutes and 4 seconds.

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@CHANGELOG.md`:
- Line 23: The changelog entry "Guarded all OAuth authorization-server route
handlers with a runtime assertion that rejects HTTP 307 and 308 responses, per
RFC 9700 §4.12. [`#1163`](https://github.com/sourcebot-dev/sourcebot/pull/1163)"
is missing the enterprise-only prefix; update that line to prepend "[EE]" to the
entry (so it reads starting with "[EE] Guarded all OAuth authorization-server
route handlers...") to comply with the changelog rules.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 70b33b5d-68e3-41db-b58e-c2a6a3a88fc1

📥 Commits

Reviewing files that changed from the base of the PR and between d691e90 and afdbe91.

📒 Files selected for processing (8)
  • CHANGELOG.md
  • packages/web/src/app/api/(server)/ee/.well-known/oauth-authorization-server/route.ts
  • packages/web/src/app/api/(server)/ee/.well-known/oauth-protected-resource/[...path]/route.ts
  • packages/web/src/app/api/(server)/ee/oauth/register/route.ts
  • packages/web/src/app/api/(server)/ee/oauth/revoke/route.ts
  • packages/web/src/app/api/(server)/ee/oauth/token/route.ts
  • packages/web/src/ee/features/oauth/apiHandler.test.ts
  • packages/web/src/ee/features/oauth/apiHandler.ts

Comment threadCHANGELOG.md
@brendan-kellam
brendan-kellam merged commit 59e0f0e into mainApr 30, 2026
10 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/oauth-307-redirect-guard-SOU-945 branch April 30, 2026 04:43
@github-actionsgithub-actionsBot mentioned this pull request Apr 30, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

chore(web): guard OAuth API routes against 307/308 redirects - #1163

Merged
brendan-kellam merged 2 commits into
mainfrom
brendan/oauth-307-redirect-guard-SOU-945
Apr 30, 2026
Merged

chore(web): guard OAuth API routes against 307/308 redirects#1163
brendan-kellam merged 2 commits into
mainfrom
brendan/oauth-307-redirect-guard-SOU-945

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Apr 30, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-945

Summary

  • Adds packages/web/src/ee/features/oauth/apiHandler.ts — a thin wrapper around apiHandler that throws if the wrapped handler ever returns HTTP 307 or 308. Per RFC 9700 §4.12, the OAuth authorization server must not use 307/308 on redirects carrying user credentials, since those statuses preserve the request method and body. The error message cites the spec.
  • Swaps apiHandleroauthApiHandler in every authorization-server route handler:
    • app/api/(server)/ee/oauth/token/route.ts
    • app/api/(server)/ee/oauth/register/route.ts
    • app/api/(server)/ee/oauth/revoke/route.ts
    • app/api/(server)/ee/.well-known/oauth-authorization-server/route.ts (RFC 8414)
    • app/api/(server)/ee/.well-known/oauth-protected-resource/[...path]/route.ts (RFC 9728)
  • Adds unit tests for the wrapper covering pass-through (200/302/303/400) and rejection (307/308) cases.

This is defense-in-depth on top of the existing posture: no authorization-server endpoint emits 307 or 308 today, but this wrapper makes regressions fail at request time rather than ship silently.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features

    • OAuth authorization-server routes now reject HTTP 307 and 308 responses at runtime.
  • Tests

    • Added test coverage for OAuth handler validation of HTTP redirect statuses.

Adds `oauthApiHandler`, a thin wrapper around `apiHandler` that throws
if the wrapped handler ever returns an HTTP 307 or 308 response. Per
RFC 9700 §4.12, an OAuth authorization server must not use 307/308 on
redirects that could carry user credentials, since those status codes
preserve the request method and body.
Wires `oauthApiHandler` into all five authorization-server route
handlers — the token, register, and revoke endpoints under
`/api/ee/oauth/*`, plus the two RFC 8414 / RFC 9728 discovery endpoints
under `/api/ee/.well-known/*` — so any future change that accidentally
introduces a 307/308 from these routes throws at request time rather
than silently shipping.
Includes unit tests verifying the wrapper passes through 200/302/303/400
responses unchanged and throws on 307 and 308.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Apr 30, 2026

Copy link
Copy Markdown
Contributor

Walkthrough

This PR introduces a runtime guard for OAuth authorization-server route handlers that rejects HTTP 307 and 308 redirect responses in accordance with RFC 9700 §4.12. A new oauthApiHandler wrapper is implemented and applied across five OAuth endpoint routes.

Changes

Cohort / File(s)Summary
Documentation
CHANGELOG.md
Added "Changed" entry documenting the runtime guard for HTTP 307/308 response rejection on OAuth routes.
OAuth Route Handlers
packages/web/src/app/api/(server)/ee/.well-known/oauth-authorization-server/route.ts, packages/web/src/app/api/(server)/ee/.well-known/oauth-protected-resource/[...path]/route.ts, packages/web/src/app/api/(server)/ee/oauth/register/route.ts, packages/web/src/app/api/(server)/ee/oauth/revoke/route.ts, packages/web/src/app/api/(server)/ee/oauth/token/route.ts
Replaced apiHandler wrapper with oauthApiHandler on all exported route handlers; internal logic and request validation remain unchanged.
OAuth Handler Implementation
packages/web/src/ee/features/oauth/apiHandler.ts
New oauthApiHandler wrapper function that delegates to apiHandler and throws an error if the wrapped handler returns HTTP 307 or 308 status codes, otherwise returns the response unmodified.
Handler Tests
packages/web/src/ee/features/oauth/apiHandler.test.ts
New test suite verifying oauthApiHandler preserves status codes for 200, 302, 303, and 400 responses, and throws an RFC 9700-referencing error when encountering 307 or 308 responses.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~12 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title 'chore(web): guard OAuth API routes against 307/308 redirects' accurately and specifically describes the main change: implementing a runtime guard against HTTP 307/308 responses in OAuth routes.
Docstring Coverage✅ PassedDocstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/oauth-307-redirect-guard-SOU-945

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share
Review rate limit: 6/8 reviews remaining, refill in 14 minutes and 4 seconds.

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@CHANGELOG.md`:
- Line 23: The changelog entry "Guarded all OAuth authorization-server route
handlers with a runtime assertion that rejects HTTP 307 and 308 responses, per
RFC 9700 §4.12. [`#1163`](https://github.com/sourcebot-dev/sourcebot/pull/1163)"
is missing the enterprise-only prefix; update that line to prepend "[EE]" to the
entry (so it reads starting with "[EE] Guarded all OAuth authorization-server
route handlers...") to comply with the changelog rules.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 70b33b5d-68e3-41db-b58e-c2a6a3a88fc1

📥 Commits

Reviewing files that changed from the base of the PR and between d691e90 and afdbe91.

📒 Files selected for processing (8)
  • CHANGELOG.md
  • packages/web/src/app/api/(server)/ee/.well-known/oauth-authorization-server/route.ts
  • packages/web/src/app/api/(server)/ee/.well-known/oauth-protected-resource/[...path]/route.ts
  • packages/web/src/app/api/(server)/ee/oauth/register/route.ts
  • packages/web/src/app/api/(server)/ee/oauth/revoke/route.ts
  • packages/web/src/app/api/(server)/ee/oauth/token/route.ts
  • packages/web/src/ee/features/oauth/apiHandler.test.ts
  • packages/web/src/ee/features/oauth/apiHandler.ts

Comment threadCHANGELOG.md
@brendan-kellam
brendan-kellam merged commit 59e0f0e into mainApr 30, 2026
10 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/oauth-307-redirect-guard-SOU-945 branch April 30, 2026 04:43
@github-actionsgithub-actionsBot mentioned this pull request Apr 30, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(web): guard OAuth API routes against 307/308 redirects - #1163

Merged
brendan-kellam merged 2 commits into
mainfrom
brendan/oauth-307-redirect-guard-SOU-945
Apr 30, 2026
Merged

chore(web): guard OAuth API routes against 307/308 redirects#1163
brendan-kellam merged 2 commits into
mainfrom
brendan/oauth-307-redirect-guard-SOU-945

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Apr 30, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-945

Summary

  • Adds packages/web/src/ee/features/oauth/apiHandler.ts — a thin wrapper around apiHandler that throws if the wrapped handler ever returns HTTP 307 or 308. Per RFC 9700 §4.12, the OAuth authorization server must not use 307/308 on redirects carrying user credentials, since those statuses preserve the request method and body. The error message cites the spec.
  • Swaps apiHandleroauthApiHandler in every authorization-server route handler:
    • app/api/(server)/ee/oauth/token/route.ts
    • app/api/(server)/ee/oauth/register/route.ts
    • app/api/(server)/ee/oauth/revoke/route.ts
    • app/api/(server)/ee/.well-known/oauth-authorization-server/route.ts (RFC 8414)
    • app/api/(server)/ee/.well-known/oauth-protected-resource/[...path]/route.ts (RFC 9728)
  • Adds unit tests for the wrapper covering pass-through (200/302/303/400) and rejection (307/308) cases.

This is defense-in-depth on top of the existing posture: no authorization-server endpoint emits 307 or 308 today, but this wrapper makes regressions fail at request time rather than ship silently.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features

    • OAuth authorization-server routes now reject HTTP 307 and 308 responses at runtime.
  • Tests

    • Added test coverage for OAuth handler validation of HTTP redirect statuses.

Adds `oauthApiHandler`, a thin wrapper around `apiHandler` that throws
if the wrapped handler ever returns an HTTP 307 or 308 response. Per
RFC 9700 §4.12, an OAuth authorization server must not use 307/308 on
redirects that could carry user credentials, since those status codes
preserve the request method and body.
Wires `oauthApiHandler` into all five authorization-server route
handlers — the token, register, and revoke endpoints under
`/api/ee/oauth/*`, plus the two RFC 8414 / RFC 9728 discovery endpoints
under `/api/ee/.well-known/*` — so any future change that accidentally
introduces a 307/308 from these routes throws at request time rather
than silently shipping.
Includes unit tests verifying the wrapper passes through 200/302/303/400
responses unchanged and throws on 307 and 308.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Apr 30, 2026

Copy link
Copy Markdown
Contributor

Walkthrough

This PR introduces a runtime guard for OAuth authorization-server route handlers that rejects HTTP 307 and 308 redirect responses in accordance with RFC 9700 §4.12. A new oauthApiHandler wrapper is implemented and applied across five OAuth endpoint routes.

Changes

Cohort / File(s)Summary
Documentation
CHANGELOG.md
Added "Changed" entry documenting the runtime guard for HTTP 307/308 response rejection on OAuth routes.
OAuth Route Handlers
packages/web/src/app/api/(server)/ee/.well-known/oauth-authorization-server/route.ts, packages/web/src/app/api/(server)/ee/.well-known/oauth-protected-resource/[...path]/route.ts, packages/web/src/app/api/(server)/ee/oauth/register/route.ts, packages/web/src/app/api/(server)/ee/oauth/revoke/route.ts, packages/web/src/app/api/(server)/ee/oauth/token/route.ts
Replaced apiHandler wrapper with oauthApiHandler on all exported route handlers; internal logic and request validation remain unchanged.
OAuth Handler Implementation
packages/web/src/ee/features/oauth/apiHandler.ts
New oauthApiHandler wrapper function that delegates to apiHandler and throws an error if the wrapped handler returns HTTP 307 or 308 status codes, otherwise returns the response unmodified.
Handler Tests
packages/web/src/ee/features/oauth/apiHandler.test.ts
New test suite verifying oauthApiHandler preserves status codes for 200, 302, 303, and 400 responses, and throws an RFC 9700-referencing error when encountering 307 or 308 responses.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~12 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title 'chore(web): guard OAuth API routes against 307/308 redirects' accurately and specifically describes the main change: implementing a runtime guard against HTTP 307/308 responses in OAuth routes.
Docstring Coverage✅ PassedDocstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/oauth-307-redirect-guard-SOU-945

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share
Review rate limit: 6/8 reviews remaining, refill in 14 minutes and 4 seconds.

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@CHANGELOG.md`:
- Line 23: The changelog entry "Guarded all OAuth authorization-server route
handlers with a runtime assertion that rejects HTTP 307 and 308 responses, per
RFC 9700 §4.12. [`#1163`](https://github.com/sourcebot-dev/sourcebot/pull/1163)"
is missing the enterprise-only prefix; update that line to prepend "[EE]" to the
entry (so it reads starting with "[EE] Guarded all OAuth authorization-server
route handlers...") to comply with the changelog rules.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 70b33b5d-68e3-41db-b58e-c2a6a3a88fc1

📥 Commits

Reviewing files that changed from the base of the PR and between d691e90 and afdbe91.

📒 Files selected for processing (8)
  • CHANGELOG.md
  • packages/web/src/app/api/(server)/ee/.well-known/oauth-authorization-server/route.ts
  • packages/web/src/app/api/(server)/ee/.well-known/oauth-protected-resource/[...path]/route.ts
  • packages/web/src/app/api/(server)/ee/oauth/register/route.ts
  • packages/web/src/app/api/(server)/ee/oauth/revoke/route.ts
  • packages/web/src/app/api/(server)/ee/oauth/token/route.ts
  • packages/web/src/ee/features/oauth/apiHandler.test.ts
  • packages/web/src/ee/features/oauth/apiHandler.ts

Comment threadCHANGELOG.md
@brendan-kellam
brendan-kellam merged commit 59e0f0e into mainApr 30, 2026
10 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/oauth-307-redirect-guard-SOU-945 branch April 30, 2026 04:43
@github-actionsgithub-actionsBot mentioned this pull request Apr 30, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(web): guard OAuth API routes against 307/308 redirects - #1163

Merged
brendan-kellam merged 2 commits into
mainfrom
brendan/oauth-307-redirect-guard-SOU-945
Apr 30, 2026
Merged

chore(web): guard OAuth API routes against 307/308 redirects#1163
brendan-kellam merged 2 commits into
mainfrom
brendan/oauth-307-redirect-guard-SOU-945

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Apr 30, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-945

Summary

  • Adds packages/web/src/ee/features/oauth/apiHandler.ts — a thin wrapper around apiHandler that throws if the wrapped handler ever returns HTTP 307 or 308. Per RFC 9700 §4.12, the OAuth authorization server must not use 307/308 on redirects carrying user credentials, since those statuses preserve the request method and body. The error message cites the spec.
  • Swaps apiHandleroauthApiHandler in every authorization-server route handler:
    • app/api/(server)/ee/oauth/token/route.ts
    • app/api/(server)/ee/oauth/register/route.ts
    • app/api/(server)/ee/oauth/revoke/route.ts
    • app/api/(server)/ee/.well-known/oauth-authorization-server/route.ts (RFC 8414)
    • app/api/(server)/ee/.well-known/oauth-protected-resource/[...path]/route.ts (RFC 9728)
  • Adds unit tests for the wrapper covering pass-through (200/302/303/400) and rejection (307/308) cases.

This is defense-in-depth on top of the existing posture: no authorization-server endpoint emits 307 or 308 today, but this wrapper makes regressions fail at request time rather than ship silently.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features

    • OAuth authorization-server routes now reject HTTP 307 and 308 responses at runtime.
  • Tests

    • Added test coverage for OAuth handler validation of HTTP redirect statuses.

Adds `oauthApiHandler`, a thin wrapper around `apiHandler` that throws
if the wrapped handler ever returns an HTTP 307 or 308 response. Per
RFC 9700 §4.12, an OAuth authorization server must not use 307/308 on
redirects that could carry user credentials, since those status codes
preserve the request method and body.
Wires `oauthApiHandler` into all five authorization-server route
handlers — the token, register, and revoke endpoints under
`/api/ee/oauth/*`, plus the two RFC 8414 / RFC 9728 discovery endpoints
under `/api/ee/.well-known/*` — so any future change that accidentally
introduces a 307/308 from these routes throws at request time rather
than silently shipping.
Includes unit tests verifying the wrapper passes through 200/302/303/400
responses unchanged and throws on 307 and 308.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Apr 30, 2026

Copy link
Copy Markdown
Contributor

Walkthrough

This PR introduces a runtime guard for OAuth authorization-server route handlers that rejects HTTP 307 and 308 redirect responses in accordance with RFC 9700 §4.12. A new oauthApiHandler wrapper is implemented and applied across five OAuth endpoint routes.

Changes

Cohort / File(s)Summary
Documentation
CHANGELOG.md
Added "Changed" entry documenting the runtime guard for HTTP 307/308 response rejection on OAuth routes.
OAuth Route Handlers
packages/web/src/app/api/(server)/ee/.well-known/oauth-authorization-server/route.ts, packages/web/src/app/api/(server)/ee/.well-known/oauth-protected-resource/[...path]/route.ts, packages/web/src/app/api/(server)/ee/oauth/register/route.ts, packages/web/src/app/api/(server)/ee/oauth/revoke/route.ts, packages/web/src/app/api/(server)/ee/oauth/token/route.ts
Replaced apiHandler wrapper with oauthApiHandler on all exported route handlers; internal logic and request validation remain unchanged.
OAuth Handler Implementation
packages/web/src/ee/features/oauth/apiHandler.ts
New oauthApiHandler wrapper function that delegates to apiHandler and throws an error if the wrapped handler returns HTTP 307 or 308 status codes, otherwise returns the response unmodified.
Handler Tests
packages/web/src/ee/features/oauth/apiHandler.test.ts
New test suite verifying oauthApiHandler preserves status codes for 200, 302, 303, and 400 responses, and throws an RFC 9700-referencing error when encountering 307 or 308 responses.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~12 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title 'chore(web): guard OAuth API routes against 307/308 redirects' accurately and specifically describes the main change: implementing a runtime guard against HTTP 307/308 responses in OAuth routes.
Docstring Coverage✅ PassedDocstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/oauth-307-redirect-guard-SOU-945

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share
Review rate limit: 6/8 reviews remaining, refill in 14 minutes and 4 seconds.

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@CHANGELOG.md`:
- Line 23: The changelog entry "Guarded all OAuth authorization-server route
handlers with a runtime assertion that rejects HTTP 307 and 308 responses, per
RFC 9700 §4.12. [`#1163`](https://github.com/sourcebot-dev/sourcebot/pull/1163)"
is missing the enterprise-only prefix; update that line to prepend "[EE]" to the
entry (so it reads starting with "[EE] Guarded all OAuth authorization-server
route handlers...") to comply with the changelog rules.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 70b33b5d-68e3-41db-b58e-c2a6a3a88fc1

📥 Commits

Reviewing files that changed from the base of the PR and between d691e90 and afdbe91.

📒 Files selected for processing (8)
  • CHANGELOG.md
  • packages/web/src/app/api/(server)/ee/.well-known/oauth-authorization-server/route.ts
  • packages/web/src/app/api/(server)/ee/.well-known/oauth-protected-resource/[...path]/route.ts
  • packages/web/src/app/api/(server)/ee/oauth/register/route.ts
  • packages/web/src/app/api/(server)/ee/oauth/revoke/route.ts
  • packages/web/src/app/api/(server)/ee/oauth/token/route.ts
  • packages/web/src/ee/features/oauth/apiHandler.test.ts
  • packages/web/src/ee/features/oauth/apiHandler.ts

Comment threadCHANGELOG.md
@brendan-kellam
brendan-kellam merged commit 59e0f0e into mainApr 30, 2026
10 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/oauth-307-redirect-guard-SOU-945 branch April 30, 2026 04:43
@github-actionsgithub-actionsBot mentioned this pull request Apr 30, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

chore(web): guard OAuth API routes against 307/308 redirects - #1163

Merged
brendan-kellam merged 2 commits into
mainfrom
brendan/oauth-307-redirect-guard-SOU-945
Apr 30, 2026
Merged

chore(web): guard OAuth API routes against 307/308 redirects#1163
brendan-kellam merged 2 commits into
mainfrom
brendan/oauth-307-redirect-guard-SOU-945

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Apr 30, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-945

Summary

  • Adds packages/web/src/ee/features/oauth/apiHandler.ts — a thin wrapper around apiHandler that throws if the wrapped handler ever returns HTTP 307 or 308. Per RFC 9700 §4.12, the OAuth authorization server must not use 307/308 on redirects carrying user credentials, since those statuses preserve the request method and body. The error message cites the spec.
  • Swaps apiHandleroauthApiHandler in every authorization-server route handler:
    • app/api/(server)/ee/oauth/token/route.ts
    • app/api/(server)/ee/oauth/register/route.ts
    • app/api/(server)/ee/oauth/revoke/route.ts
    • app/api/(server)/ee/.well-known/oauth-authorization-server/route.ts (RFC 8414)
    • app/api/(server)/ee/.well-known/oauth-protected-resource/[...path]/route.ts (RFC 9728)
  • Adds unit tests for the wrapper covering pass-through (200/302/303/400) and rejection (307/308) cases.

This is defense-in-depth on top of the existing posture: no authorization-server endpoint emits 307 or 308 today, but this wrapper makes regressions fail at request time rather than ship silently.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features

    • OAuth authorization-server routes now reject HTTP 307 and 308 responses at runtime.
  • Tests

    • Added test coverage for OAuth handler validation of HTTP redirect statuses.

Adds `oauthApiHandler`, a thin wrapper around `apiHandler` that throws
if the wrapped handler ever returns an HTTP 307 or 308 response. Per
RFC 9700 §4.12, an OAuth authorization server must not use 307/308 on
redirects that could carry user credentials, since those status codes
preserve the request method and body.
Wires `oauthApiHandler` into all five authorization-server route
handlers — the token, register, and revoke endpoints under
`/api/ee/oauth/*`, plus the two RFC 8414 / RFC 9728 discovery endpoints
under `/api/ee/.well-known/*` — so any future change that accidentally
introduces a 307/308 from these routes throws at request time rather
than silently shipping.
Includes unit tests verifying the wrapper passes through 200/302/303/400
responses unchanged and throws on 307 and 308.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Apr 30, 2026

Copy link
Copy Markdown
Contributor

Walkthrough

This PR introduces a runtime guard for OAuth authorization-server route handlers that rejects HTTP 307 and 308 redirect responses in accordance with RFC 9700 §4.12. A new oauthApiHandler wrapper is implemented and applied across five OAuth endpoint routes.

Changes

Cohort / File(s)Summary
Documentation
CHANGELOG.md
Added "Changed" entry documenting the runtime guard for HTTP 307/308 response rejection on OAuth routes.
OAuth Route Handlers
packages/web/src/app/api/(server)/ee/.well-known/oauth-authorization-server/route.ts, packages/web/src/app/api/(server)/ee/.well-known/oauth-protected-resource/[...path]/route.ts, packages/web/src/app/api/(server)/ee/oauth/register/route.ts, packages/web/src/app/api/(server)/ee/oauth/revoke/route.ts, packages/web/src/app/api/(server)/ee/oauth/token/route.ts
Replaced apiHandler wrapper with oauthApiHandler on all exported route handlers; internal logic and request validation remain unchanged.
OAuth Handler Implementation
packages/web/src/ee/features/oauth/apiHandler.ts
New oauthApiHandler wrapper function that delegates to apiHandler and throws an error if the wrapped handler returns HTTP 307 or 308 status codes, otherwise returns the response unmodified.
Handler Tests
packages/web/src/ee/features/oauth/apiHandler.test.ts
New test suite verifying oauthApiHandler preserves status codes for 200, 302, 303, and 400 responses, and throws an RFC 9700-referencing error when encountering 307 or 308 responses.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~12 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title 'chore(web): guard OAuth API routes against 307/308 redirects' accurately and specifically describes the main change: implementing a runtime guard against HTTP 307/308 responses in OAuth routes.
Docstring Coverage✅ PassedDocstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/oauth-307-redirect-guard-SOU-945

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share
Review rate limit: 6/8 reviews remaining, refill in 14 minutes and 4 seconds.

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@CHANGELOG.md`:
- Line 23: The changelog entry "Guarded all OAuth authorization-server route
handlers with a runtime assertion that rejects HTTP 307 and 308 responses, per
RFC 9700 §4.12. [`#1163`](https://github.com/sourcebot-dev/sourcebot/pull/1163)"
is missing the enterprise-only prefix; update that line to prepend "[EE]" to the
entry (so it reads starting with "[EE] Guarded all OAuth authorization-server
route handlers...") to comply with the changelog rules.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 70b33b5d-68e3-41db-b58e-c2a6a3a88fc1

📥 Commits

Reviewing files that changed from the base of the PR and between d691e90 and afdbe91.

📒 Files selected for processing (8)
  • CHANGELOG.md
  • packages/web/src/app/api/(server)/ee/.well-known/oauth-authorization-server/route.ts
  • packages/web/src/app/api/(server)/ee/.well-known/oauth-protected-resource/[...path]/route.ts
  • packages/web/src/app/api/(server)/ee/oauth/register/route.ts
  • packages/web/src/app/api/(server)/ee/oauth/revoke/route.ts
  • packages/web/src/app/api/(server)/ee/oauth/token/route.ts
  • packages/web/src/ee/features/oauth/apiHandler.test.ts
  • packages/web/src/ee/features/oauth/apiHandler.ts

Comment threadCHANGELOG.md
@brendan-kellam
brendan-kellam merged commit 59e0f0e into mainApr 30, 2026
10 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/oauth-307-redirect-guard-SOU-945 branch April 30, 2026 04:43
@github-actionsgithub-actionsBot mentioned this pull request Apr 30, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(web): guard OAuth API routes against 307/308 redirects - #1163

Merged
brendan-kellam merged 2 commits into
mainfrom
brendan/oauth-307-redirect-guard-SOU-945
Apr 30, 2026
Merged

chore(web): guard OAuth API routes against 307/308 redirects#1163
brendan-kellam merged 2 commits into
mainfrom
brendan/oauth-307-redirect-guard-SOU-945

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Apr 30, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-945

Summary

  • Adds packages/web/src/ee/features/oauth/apiHandler.ts — a thin wrapper around apiHandler that throws if the wrapped handler ever returns HTTP 307 or 308. Per RFC 9700 §4.12, the OAuth authorization server must not use 307/308 on redirects carrying user credentials, since those statuses preserve the request method and body. The error message cites the spec.
  • Swaps apiHandleroauthApiHandler in every authorization-server route handler:
    • app/api/(server)/ee/oauth/token/route.ts
    • app/api/(server)/ee/oauth/register/route.ts
    • app/api/(server)/ee/oauth/revoke/route.ts
    • app/api/(server)/ee/.well-known/oauth-authorization-server/route.ts (RFC 8414)
    • app/api/(server)/ee/.well-known/oauth-protected-resource/[...path]/route.ts (RFC 9728)
  • Adds unit tests for the wrapper covering pass-through (200/302/303/400) and rejection (307/308) cases.

This is defense-in-depth on top of the existing posture: no authorization-server endpoint emits 307 or 308 today, but this wrapper makes regressions fail at request time rather than ship silently.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features

    • OAuth authorization-server routes now reject HTTP 307 and 308 responses at runtime.
  • Tests

    • Added test coverage for OAuth handler validation of HTTP redirect statuses.

Adds `oauthApiHandler`, a thin wrapper around `apiHandler` that throws
if the wrapped handler ever returns an HTTP 307 or 308 response. Per
RFC 9700 §4.12, an OAuth authorization server must not use 307/308 on
redirects that could carry user credentials, since those status codes
preserve the request method and body.
Wires `oauthApiHandler` into all five authorization-server route
handlers — the token, register, and revoke endpoints under
`/api/ee/oauth/*`, plus the two RFC 8414 / RFC 9728 discovery endpoints
under `/api/ee/.well-known/*` — so any future change that accidentally
introduces a 307/308 from these routes throws at request time rather
than silently shipping.
Includes unit tests verifying the wrapper passes through 200/302/303/400
responses unchanged and throws on 307 and 308.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Apr 30, 2026

Copy link
Copy Markdown
Contributor

Walkthrough

This PR introduces a runtime guard for OAuth authorization-server route handlers that rejects HTTP 307 and 308 redirect responses in accordance with RFC 9700 §4.12. A new oauthApiHandler wrapper is implemented and applied across five OAuth endpoint routes.

Changes

Cohort / File(s)Summary
Documentation
CHANGELOG.md
Added "Changed" entry documenting the runtime guard for HTTP 307/308 response rejection on OAuth routes.
OAuth Route Handlers
packages/web/src/app/api/(server)/ee/.well-known/oauth-authorization-server/route.ts, packages/web/src/app/api/(server)/ee/.well-known/oauth-protected-resource/[...path]/route.ts, packages/web/src/app/api/(server)/ee/oauth/register/route.ts, packages/web/src/app/api/(server)/ee/oauth/revoke/route.ts, packages/web/src/app/api/(server)/ee/oauth/token/route.ts
Replaced apiHandler wrapper with oauthApiHandler on all exported route handlers; internal logic and request validation remain unchanged.
OAuth Handler Implementation
packages/web/src/ee/features/oauth/apiHandler.ts
New oauthApiHandler wrapper function that delegates to apiHandler and throws an error if the wrapped handler returns HTTP 307 or 308 status codes, otherwise returns the response unmodified.
Handler Tests
packages/web/src/ee/features/oauth/apiHandler.test.ts
New test suite verifying oauthApiHandler preserves status codes for 200, 302, 303, and 400 responses, and throws an RFC 9700-referencing error when encountering 307 or 308 responses.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~12 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title 'chore(web): guard OAuth API routes against 307/308 redirects' accurately and specifically describes the main change: implementing a runtime guard against HTTP 307/308 responses in OAuth routes.
Docstring Coverage✅ PassedDocstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/oauth-307-redirect-guard-SOU-945

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share
Review rate limit: 6/8 reviews remaining, refill in 14 minutes and 4 seconds.

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@CHANGELOG.md`:
- Line 23: The changelog entry "Guarded all OAuth authorization-server route
handlers with a runtime assertion that rejects HTTP 307 and 308 responses, per
RFC 9700 §4.12. [`#1163`](https://github.com/sourcebot-dev/sourcebot/pull/1163)"
is missing the enterprise-only prefix; update that line to prepend "[EE]" to the
entry (so it reads starting with "[EE] Guarded all OAuth authorization-server
route handlers...") to comply with the changelog rules.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 70b33b5d-68e3-41db-b58e-c2a6a3a88fc1

📥 Commits

Reviewing files that changed from the base of the PR and between d691e90 and afdbe91.

📒 Files selected for processing (8)
  • CHANGELOG.md
  • packages/web/src/app/api/(server)/ee/.well-known/oauth-authorization-server/route.ts
  • packages/web/src/app/api/(server)/ee/.well-known/oauth-protected-resource/[...path]/route.ts
  • packages/web/src/app/api/(server)/ee/oauth/register/route.ts
  • packages/web/src/app/api/(server)/ee/oauth/revoke/route.ts
  • packages/web/src/app/api/(server)/ee/oauth/token/route.ts
  • packages/web/src/ee/features/oauth/apiHandler.test.ts
  • packages/web/src/ee/features/oauth/apiHandler.ts

Comment threadCHANGELOG.md
@brendan-kellam
brendan-kellam merged commit 59e0f0e into mainApr 30, 2026
10 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/oauth-307-redirect-guard-SOU-945 branch April 30, 2026 04:43
@github-actionsgithub-actionsBot mentioned this pull request Apr 30, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(web): guard OAuth API routes against 307/308 redirects - #1163

Merged
brendan-kellam merged 2 commits into
mainfrom
brendan/oauth-307-redirect-guard-SOU-945
Apr 30, 2026
Merged

chore(web): guard OAuth API routes against 307/308 redirects#1163
brendan-kellam merged 2 commits into
mainfrom
brendan/oauth-307-redirect-guard-SOU-945

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Apr 30, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-945

Summary

  • Adds packages/web/src/ee/features/oauth/apiHandler.ts — a thin wrapper around apiHandler that throws if the wrapped handler ever returns HTTP 307 or 308. Per RFC 9700 §4.12, the OAuth authorization server must not use 307/308 on redirects carrying user credentials, since those statuses preserve the request method and body. The error message cites the spec.
  • Swaps apiHandleroauthApiHandler in every authorization-server route handler:
    • app/api/(server)/ee/oauth/token/route.ts
    • app/api/(server)/ee/oauth/register/route.ts
    • app/api/(server)/ee/oauth/revoke/route.ts
    • app/api/(server)/ee/.well-known/oauth-authorization-server/route.ts (RFC 8414)
    • app/api/(server)/ee/.well-known/oauth-protected-resource/[...path]/route.ts (RFC 9728)
  • Adds unit tests for the wrapper covering pass-through (200/302/303/400) and rejection (307/308) cases.

This is defense-in-depth on top of the existing posture: no authorization-server endpoint emits 307 or 308 today, but this wrapper makes regressions fail at request time rather than ship silently.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features

    • OAuth authorization-server routes now reject HTTP 307 and 308 responses at runtime.
  • Tests

    • Added test coverage for OAuth handler validation of HTTP redirect statuses.

Adds `oauthApiHandler`, a thin wrapper around `apiHandler` that throws
if the wrapped handler ever returns an HTTP 307 or 308 response. Per
RFC 9700 §4.12, an OAuth authorization server must not use 307/308 on
redirects that could carry user credentials, since those status codes
preserve the request method and body.
Wires `oauthApiHandler` into all five authorization-server route
handlers — the token, register, and revoke endpoints under
`/api/ee/oauth/*`, plus the two RFC 8414 / RFC 9728 discovery endpoints
under `/api/ee/.well-known/*` — so any future change that accidentally
introduces a 307/308 from these routes throws at request time rather
than silently shipping.
Includes unit tests verifying the wrapper passes through 200/302/303/400
responses unchanged and throws on 307 and 308.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Apr 30, 2026

Copy link
Copy Markdown
Contributor

Walkthrough

This PR introduces a runtime guard for OAuth authorization-server route handlers that rejects HTTP 307 and 308 redirect responses in accordance with RFC 9700 §4.12. A new oauthApiHandler wrapper is implemented and applied across five OAuth endpoint routes.

Changes

Cohort / File(s)Summary
Documentation
CHANGELOG.md
Added "Changed" entry documenting the runtime guard for HTTP 307/308 response rejection on OAuth routes.
OAuth Route Handlers
packages/web/src/app/api/(server)/ee/.well-known/oauth-authorization-server/route.ts, packages/web/src/app/api/(server)/ee/.well-known/oauth-protected-resource/[...path]/route.ts, packages/web/src/app/api/(server)/ee/oauth/register/route.ts, packages/web/src/app/api/(server)/ee/oauth/revoke/route.ts, packages/web/src/app/api/(server)/ee/oauth/token/route.ts
Replaced apiHandler wrapper with oauthApiHandler on all exported route handlers; internal logic and request validation remain unchanged.
OAuth Handler Implementation
packages/web/src/ee/features/oauth/apiHandler.ts
New oauthApiHandler wrapper function that delegates to apiHandler and throws an error if the wrapped handler returns HTTP 307 or 308 status codes, otherwise returns the response unmodified.
Handler Tests
packages/web/src/ee/features/oauth/apiHandler.test.ts
New test suite verifying oauthApiHandler preserves status codes for 200, 302, 303, and 400 responses, and throws an RFC 9700-referencing error when encountering 307 or 308 responses.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~12 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title 'chore(web): guard OAuth API routes against 307/308 redirects' accurately and specifically describes the main change: implementing a runtime guard against HTTP 307/308 responses in OAuth routes.
Docstring Coverage✅ PassedDocstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/oauth-307-redirect-guard-SOU-945

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share
Review rate limit: 6/8 reviews remaining, refill in 14 minutes and 4 seconds.

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@CHANGELOG.md`:
- Line 23: The changelog entry "Guarded all OAuth authorization-server route
handlers with a runtime assertion that rejects HTTP 307 and 308 responses, per
RFC 9700 §4.12. [`#1163`](https://github.com/sourcebot-dev/sourcebot/pull/1163)"
is missing the enterprise-only prefix; update that line to prepend "[EE]" to the
entry (so it reads starting with "[EE] Guarded all OAuth authorization-server
route handlers...") to comply with the changelog rules.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 70b33b5d-68e3-41db-b58e-c2a6a3a88fc1

📥 Commits

Reviewing files that changed from the base of the PR and between d691e90 and afdbe91.

📒 Files selected for processing (8)
  • CHANGELOG.md
  • packages/web/src/app/api/(server)/ee/.well-known/oauth-authorization-server/route.ts
  • packages/web/src/app/api/(server)/ee/.well-known/oauth-protected-resource/[...path]/route.ts
  • packages/web/src/app/api/(server)/ee/oauth/register/route.ts
  • packages/web/src/app/api/(server)/ee/oauth/revoke/route.ts
  • packages/web/src/app/api/(server)/ee/oauth/token/route.ts
  • packages/web/src/ee/features/oauth/apiHandler.test.ts
  • packages/web/src/ee/features/oauth/apiHandler.ts

Comment threadCHANGELOG.md
@brendan-kellam
brendan-kellam merged commit 59e0f0e into mainApr 30, 2026
10 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/oauth-307-redirect-guard-SOU-945 branch April 30, 2026 04:43
@github-actionsgithub-actionsBot mentioned this pull request Apr 30, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

chore(web): guard OAuth API routes against 307/308 redirects - #1163

Merged
brendan-kellam merged 2 commits into
mainfrom
brendan/oauth-307-redirect-guard-SOU-945
Apr 30, 2026
Merged

chore(web): guard OAuth API routes against 307/308 redirects#1163
brendan-kellam merged 2 commits into
mainfrom
brendan/oauth-307-redirect-guard-SOU-945

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Apr 30, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-945

Summary

  • Adds packages/web/src/ee/features/oauth/apiHandler.ts — a thin wrapper around apiHandler that throws if the wrapped handler ever returns HTTP 307 or 308. Per RFC 9700 §4.12, the OAuth authorization server must not use 307/308 on redirects carrying user credentials, since those statuses preserve the request method and body. The error message cites the spec.
  • Swaps apiHandleroauthApiHandler in every authorization-server route handler:
    • app/api/(server)/ee/oauth/token/route.ts
    • app/api/(server)/ee/oauth/register/route.ts
    • app/api/(server)/ee/oauth/revoke/route.ts
    • app/api/(server)/ee/.well-known/oauth-authorization-server/route.ts (RFC 8414)
    • app/api/(server)/ee/.well-known/oauth-protected-resource/[...path]/route.ts (RFC 9728)
  • Adds unit tests for the wrapper covering pass-through (200/302/303/400) and rejection (307/308) cases.

This is defense-in-depth on top of the existing posture: no authorization-server endpoint emits 307 or 308 today, but this wrapper makes regressions fail at request time rather than ship silently.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features

    • OAuth authorization-server routes now reject HTTP 307 and 308 responses at runtime.
  • Tests

    • Added test coverage for OAuth handler validation of HTTP redirect statuses.

Adds `oauthApiHandler`, a thin wrapper around `apiHandler` that throws
if the wrapped handler ever returns an HTTP 307 or 308 response. Per
RFC 9700 §4.12, an OAuth authorization server must not use 307/308 on
redirects that could carry user credentials, since those status codes
preserve the request method and body.
Wires `oauthApiHandler` into all five authorization-server route
handlers — the token, register, and revoke endpoints under
`/api/ee/oauth/*`, plus the two RFC 8414 / RFC 9728 discovery endpoints
under `/api/ee/.well-known/*` — so any future change that accidentally
introduces a 307/308 from these routes throws at request time rather
than silently shipping.
Includes unit tests verifying the wrapper passes through 200/302/303/400
responses unchanged and throws on 307 and 308.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Apr 30, 2026

Copy link
Copy Markdown
Contributor

Walkthrough

This PR introduces a runtime guard for OAuth authorization-server route handlers that rejects HTTP 307 and 308 redirect responses in accordance with RFC 9700 §4.12. A new oauthApiHandler wrapper is implemented and applied across five OAuth endpoint routes.

Changes

Cohort / File(s)Summary
Documentation
CHANGELOG.md
Added "Changed" entry documenting the runtime guard for HTTP 307/308 response rejection on OAuth routes.
OAuth Route Handlers
packages/web/src/app/api/(server)/ee/.well-known/oauth-authorization-server/route.ts, packages/web/src/app/api/(server)/ee/.well-known/oauth-protected-resource/[...path]/route.ts, packages/web/src/app/api/(server)/ee/oauth/register/route.ts, packages/web/src/app/api/(server)/ee/oauth/revoke/route.ts, packages/web/src/app/api/(server)/ee/oauth/token/route.ts
Replaced apiHandler wrapper with oauthApiHandler on all exported route handlers; internal logic and request validation remain unchanged.
OAuth Handler Implementation
packages/web/src/ee/features/oauth/apiHandler.ts
New oauthApiHandler wrapper function that delegates to apiHandler and throws an error if the wrapped handler returns HTTP 307 or 308 status codes, otherwise returns the response unmodified.
Handler Tests
packages/web/src/ee/features/oauth/apiHandler.test.ts
New test suite verifying oauthApiHandler preserves status codes for 200, 302, 303, and 400 responses, and throws an RFC 9700-referencing error when encountering 307 or 308 responses.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~12 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title 'chore(web): guard OAuth API routes against 307/308 redirects' accurately and specifically describes the main change: implementing a runtime guard against HTTP 307/308 responses in OAuth routes.
Docstring Coverage✅ PassedDocstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/oauth-307-redirect-guard-SOU-945

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share
Review rate limit: 6/8 reviews remaining, refill in 14 minutes and 4 seconds.

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@CHANGELOG.md`:
- Line 23: The changelog entry "Guarded all OAuth authorization-server route
handlers with a runtime assertion that rejects HTTP 307 and 308 responses, per
RFC 9700 §4.12. [`#1163`](https://github.com/sourcebot-dev/sourcebot/pull/1163)"
is missing the enterprise-only prefix; update that line to prepend "[EE]" to the
entry (so it reads starting with "[EE] Guarded all OAuth authorization-server
route handlers...") to comply with the changelog rules.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 70b33b5d-68e3-41db-b58e-c2a6a3a88fc1

📥 Commits

Reviewing files that changed from the base of the PR and between d691e90 and afdbe91.

📒 Files selected for processing (8)
  • CHANGELOG.md
  • packages/web/src/app/api/(server)/ee/.well-known/oauth-authorization-server/route.ts
  • packages/web/src/app/api/(server)/ee/.well-known/oauth-protected-resource/[...path]/route.ts
  • packages/web/src/app/api/(server)/ee/oauth/register/route.ts
  • packages/web/src/app/api/(server)/ee/oauth/revoke/route.ts
  • packages/web/src/app/api/(server)/ee/oauth/token/route.ts
  • packages/web/src/ee/features/oauth/apiHandler.test.ts
  • packages/web/src/ee/features/oauth/apiHandler.ts

Comment threadCHANGELOG.md
@brendan-kellam
brendan-kellam merged commit 59e0f0e into mainApr 30, 2026
10 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/oauth-307-redirect-guard-SOU-945 branch April 30, 2026 04:43
@github-actionsgithub-actionsBot mentioned this pull request Apr 30, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam