Conversation
WordPress Playground🚀 Your PR has been built and is ready for testing in WordPress Playground! |
n7studios
marked this pull request as ready for review
September 30, 2026 15:26
n7studios
requested review from
a team,
ciccio-kit and
noelherrick
and removed request for
a team
September 30, 2026 15:26
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Validates OAuth authorization requests before exchanging the authorization code for an access token:
manage_optionscapability.Kit's OAuth redirect only keeps the
page,tabandsectionparameters from the return URL, so the nonce is sent and returned insection(section=kit-oauth-{nonce}).The OAuth callback handler is only registered when the Plugin has no access token, so this affects connecting a not-yet-connected site; an already-connected site's credentials cannot be overwritten via this flow.
convertkit_get_oauth_url()is added to build the OAuth URL with the nonce, and is used by the Connect button, the "authorization failed" admin notice and the no-credentials meta box.Testing
testAuthorizationCodeNotExchangedWhenUnauthenticated: confirms no authorization code is exchanged, and no access token is stored, for requests from logged-out users (viaadmin-post.php, which runsadmin_initfor unauthenticated requests).testAuthorizationCodeNotExchangedWithoutNonce: confirms the same when an Administrator's request has a missing or invalid nonce.testNoCredentials,PostCestandPageCest: updated to decode the OAuthstateparameter and check the return URL includes the nonce.Checklist