Commit graph

4 commits

Author SHA1 Message Date
Adam Moussa
d1b91ae661 Read OAuth client credentials from Secrets Manager at runtime
Removes CloudFormation dynamic references for clientId/clientSecret
env vars. Credentials are now fetched from Secrets Manager at runtime
so secret updates don't require a redeploy.
2026-04-13 20:22:21 -04:00
Adam Moussa
9463a07e50 Use Intuit discovery document for OAuth endpoints
Fetch authorization, token, and revocation endpoints from Intuit's
.well-known/openid_configuration at runtime instead of hardcoding.
Cached per Lambda instance for performance.
2026-04-13 19:59:23 -04:00
Adam Moussa
266fe833fd Fix Intuit security compliance issues
- CSRF: store OAuth state in Secure/HttpOnly cookie, validate on callback
- Cache-Control: add no-cache, no-store headers to all responses
- Sensitive info: callback errors now 302 redirect instead of returning HTML
- Logging: remove realmId and sanitize error logs to prevent QBO data leaks
2026-04-13 19:49:29 -04:00
Adam Moussa
acfe8185a9 Add QBO OAuth endpoints for QuickBooks app listing
Adds /qbo/connect, /qbo/callback, /qbo/disconnect, and /qbo/launch
routes to bot.seahaven.com for Intuit app store compliance. Also
updates qbo-lookup to persist rotated refresh tokens automatically.
2026-04-13 19:31:13 -04:00