[HN Gopher] How to avoid leaking your customer's source code wit...
       ___________________________________________________________________
        
       How to avoid leaking your customer's source code with GitHub apps
        
       Author : grinnick
       Score  : 25 points
       Date   : 2021-11-03 14:22 UTC (8 hours ago)
        
 (HTM) web link (roadie.io)
 (TXT) w3m dump (roadie.io)
        
       | eranation wrote:
       | Good article and agree with the recommendations, I'm trying to
       | understand the attack flow though. You perform an actual
       | installation and get a valid authorization code, but replace the
       | actual installation ID with another (that the user has no access
       | to)?
       | 
       | This is a major issue then from GitHub's side. I think what
       | GitHub should do is just like with Oauth apps, allow you to
       | provide a state (assuming the flow is starting from the SaaS app,
       | not from the GitHub marketplace, I assume you can't send a state
       | since it's sort of like an "IdP initiated" flow in case you start
       | the installation from the github marketplace, but they should let
       | you opt out and require a state. There is a reason why things
       | like PKCE and such exist.
        
         | brianfletcher wrote:
         | If you use the setup url callback, you don't get any
         | authorization code just an installation id and the setup
         | action. So there is no means to verify that the user honestly
         | owns the installation that they are providing. Because the
         | number is so short, it's easy to guess every combination.
        
       | netr0ute wrote:
       | The real fix? Make all of their software open source.
        
         | yjftsjthsd-h wrote:
         | That would rather defeat the purpose...
        
       ___________________________________________________________________
       (page generated 2021-11-03 23:01 UTC)