Commit 0968598
fix(mcp): tighten 401 detection, hash OAuth state at rest
- Use word-boundary regex for 401 match in form auth heuristic
- SHA-256 hash OAuth state in DB; lookup by hash to prevent replay if DB read leaks
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>1 parent 9671131 commit 0968598
2 files changed
Lines changed: 8 additions & 3 deletions
File tree
- apps/sim
- app/workspace/[workspaceId]/settings/components/mcp/components/mcp-server-form-modal
- lib/mcp/oauth
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
520 | 520 | | |
521 | 521 | | |
522 | 522 | | |
523 | | - | |
| 523 | + | |
524 | 524 | | |
525 | 525 | | |
526 | 526 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
1 | 2 | | |
2 | 3 | | |
3 | 4 | | |
| |||
8 | 9 | | |
9 | 10 | | |
10 | 11 | | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
11 | 16 | | |
12 | 17 | | |
13 | 18 | | |
| |||
107 | 112 | | |
108 | 113 | | |
109 | 114 | | |
110 | | - | |
| 115 | + | |
111 | 116 | | |
112 | 117 | | |
113 | 118 | | |
| |||
154 | 159 | | |
155 | 160 | | |
156 | 161 | | |
157 | | - | |
| 162 | + | |
158 | 163 | | |
159 | 164 | | |
160 | 165 | | |
| |||
0 commit comments