Removes CloudFormation dynamic references for clientId/clientSecret
env vars. Credentials are now fetched from Secrets Manager at runtime
so secret updates don't require a redeploy.
Fetch authorization, token, and revocation endpoints from Intuit's
.well-known/openid_configuration at runtime instead of hardcoding.
Cached per Lambda instance for performance.
- CSRF: store OAuth state in Secure/HttpOnly cookie, validate on callback
- Cache-Control: add no-cache, no-store headers to all responses
- Sensitive info: callback errors now 302 redirect instead of returning HTML
- Logging: remove realmId and sanitize error logs to prevent QBO data leaks
Adds /qbo/connect, /qbo/callback, /qbo/disconnect, and /qbo/launch
routes to bot.seahaven.com for Intuit app store compliance. Also
updates qbo-lookup to persist rotated refresh tokens automatically.