Skip to content

OAuth: Fix Broken Access Control - #1207

Open
n7studios wants to merge 4 commits into
mainfrom
fix-oauth-broken-access-control
Open

n7studios wants to merge 4 commits into
mainfrom
fix-oauth-broken-access-control

Conversation

@n7studios

@n7studios n7studios commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Validates OAuth authorization requests before exchanging the authorization code for an access token:

  • The user must be logged in with the manage_options capability.
  • The request must include a valid nonce, which proves the same user started the Connect flow.

Kit's OAuth redirect only keeps the page, tab and section parameters from the return URL, so the nonce is sent and returned in section (section=kit-oauth-{nonce}).

The OAuth callback handler is only registered when the Plugin has no access token, so this affects connecting a not-yet-connected site; an already-connected site's credentials cannot be overwritten via this flow. convertkit_get_oauth_url() is added to build the OAuth URL with the nonce, and is used by the Connect button, the "authorization failed" admin notice and the no-credentials meta box.

Testing

  • testAuthorizationCodeNotExchangedWhenUnauthenticated: confirms no authorization code is exchanged, and no access token is stored, for requests from logged-out users (via admin-post.php, which runs admin_init for unauthenticated requests).
  • testAuthorizationCodeNotExchangedWithoutNonce: confirms the same when an Administrator's request has a missing or invalid nonce.
  • testNoCredentials, PostCest and PageCest: updated to decode the OAuth state parameter and check the return URL includes the nonce.
  • Checked manually: connecting to Kit through OAuth still works.

Checklist

@n7studios n7studios self-assigned this Sep 30, 2026
@n7studios n7studios added the bug label Sep 30, 2026
@github-actions

Copy link
Copy Markdown

WordPress Playground

🚀 Your PR has been built and is ready for testing in WordPress Playground!

Click here to test your changes in WordPress Playground

@n7studios
n7studios marked this pull request as ready for review September 30, 2026 15:26
@n7studios
n7studios requested review from a team, ciccio-kit and noelherrick and removed request for a team September 30, 2026 15:26
@n7studios n7studios added this to the 3.4.6 milestone Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

1 participant