fix(vloer): send the ClickUp token exchange in the request body #156

Merged
ryangr0 merged 1 commit from ryangr0/vloer-clickup-token-exchange-body into development 2026-10-03 00:30:44 +00:00 AGit
Owner

The ClickUp branch of Links.complete put client_id, client_secret and the
authorization code in the query string of a bodyless POST. ClickUp documents
them as body parameters, and URLs end up in proxy logs, traces and error
messages, which exposed the client secret.

The exchange now posts the three fields as a JSON body with a matching
Content-Type to a URL without a query string. The 10-second timeout and
redirect: 'error' are unchanged. A test with an intercepted fetch asserts the
URL, the body, the headers and that a refused exchange never mentions the
secret; the fake ClickUp server now reads the fields from the body.

Refs: VIK-1721

Co-Authored-By: Claude Opus 5.5 (1M context) noreply@anthropic.com

Not tried against live ClickUp; ClickUp documents JSON or form bodies for this endpoint. If live linking fails, switch to form encoding (one line).

Verified with mise run verify on the pinned toolchain (all gates passed).

Ticket: https://vikunja.webgrip.dev/tasks/1721

🤖 Generated with Claude Code

The ClickUp branch of Links.complete put client_id, client_secret and the authorization code in the query string of a bodyless POST. ClickUp documents them as body parameters, and URLs end up in proxy logs, traces and error messages, which exposed the client secret. The exchange now posts the three fields as a JSON body with a matching Content-Type to a URL without a query string. The 10-second timeout and redirect: 'error' are unchanged. A test with an intercepted fetch asserts the URL, the body, the headers and that a refused exchange never mentions the secret; the fake ClickUp server now reads the fields from the body. Refs: VIK-1721 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Not tried against live ClickUp; ClickUp documents JSON or form bodies for this endpoint. If live linking fails, switch to form encoding (one line). Verified with `mise run verify` on the pinned toolchain (all gates passed). Ticket: https://vikunja.webgrip.dev/tasks/1721 🤖 Generated with [Claude Code](https://claude.com/claude-code)
fix(vloer): send the ClickUp token exchange in the request body
Some checks failed
[Workflow] On Pull Request / release-policy (pull_request) Failing after 21s
[Workflow] On Pull Request / checks (pull_request) Successful in 5m22s
[Workflow] On Pull Request / warnings (pull_request) Successful in 0s
0f827b3e0d
The ClickUp branch of Links.complete put client_id, client_secret and the
authorization code in the query string of a bodyless POST. ClickUp documents
them as body parameters, and URLs end up in proxy logs, traces and error
messages, which exposed the client secret.

The exchange now posts the three fields as a JSON body with a matching
Content-Type to a URL without a query string. The 10-second timeout and
redirect: 'error' are unchanged. A test with an intercepted fetch asserts the
URL, the body, the headers and that a refused exchange never mentions the
secret; the fake ClickUp server now reads the fields from the body.

Refs: VIK-1721

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
ryangr0 merged commit e809348aa7 into development 2026-10-03 00:30:44 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
webgrip/unfold!156
No description provided.