This repository has been archived on 2026-08-04. You can view files and clone it, but cannot push or open issues or pull requests.
seahaven-slack-bot/lambda/qbo-oauth
Adam Moussa 266fe833fd Fix Intuit security compliance issues
- CSRF: store OAuth state in Secure/HttpOnly cookie, validate on callback
- Cache-Control: add no-cache, no-store headers to all responses
- Sensitive info: callback errors now 302 redirect instead of returning HTML
- Logging: remove realmId and sanitize error logs to prevent QBO data leaks
2026-04-13 19:49:29 -04:00
..
index.ts Fix Intuit security compliance issues 2026-04-13 19:49:29 -04:00