fix(vloer): send the ClickUp token exchange in the request body #156
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "ryangr0/vloer-clickup-token-exchange-body"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The ClickUp branch of Links.complete put client_id, client_secret and the
authorization code in the query string of a bodyless POST. ClickUp documents
them as body parameters, and URLs end up in proxy logs, traces and error
messages, which exposed the client secret.
The exchange now posts the three fields as a JSON body with a matching
Content-Type to a URL without a query string. The 10-second timeout and
redirect: 'error' are unchanged. A test with an intercepted fetch asserts the
URL, the body, the headers and that a refused exchange never mentions the
secret; the fake ClickUp server now reads the fields from the body.
Refs: VIK-1721
Co-Authored-By: Claude Opus 5.5 (1M context) noreply@anthropic.com
Not tried against live ClickUp; ClickUp documents JSON or form bodies for this endpoint. If live linking fails, switch to form encoding (one line).
Verified with
mise run verifyon the pinned toolchain (all gates passed).Ticket: https://vikunja.webgrip.dev/tasks/1721
🤖 Generated with Claude Code