[HN Gopher] How to avoid leaking your customer's source code wit...
___________________________________________________________________
How to avoid leaking your customer's source code with GitHub apps
Author : grinnick
Score : 25 points
Date : 2021-11-03 14:22 UTC (8 hours ago)
(HTM) web link (roadie.io)
(TXT) w3m dump (roadie.io)
| eranation wrote:
| Good article and agree with the recommendations, I'm trying to
| understand the attack flow though. You perform an actual
| installation and get a valid authorization code, but replace the
| actual installation ID with another (that the user has no access
| to)?
|
| This is a major issue then from GitHub's side. I think what
| GitHub should do is just like with Oauth apps, allow you to
| provide a state (assuming the flow is starting from the SaaS app,
| not from the GitHub marketplace, I assume you can't send a state
| since it's sort of like an "IdP initiated" flow in case you start
| the installation from the github marketplace, but they should let
| you opt out and require a state. There is a reason why things
| like PKCE and such exist.
| brianfletcher wrote:
| If you use the setup url callback, you don't get any
| authorization code just an installation id and the setup
| action. So there is no means to verify that the user honestly
| owns the installation that they are providing. Because the
| number is so short, it's easy to guess every combination.
| netr0ute wrote:
| The real fix? Make all of their software open source.
| yjftsjthsd-h wrote:
| That would rather defeat the purpose...
___________________________________________________________________
(page generated 2021-11-03 23:01 UTC)