From sprint-review's #1290 pass: { ...currentConfig, ...config } (routes/integrations.ts) accepts any config key from any caller who passes canDeleteIntegration — including botToken, secretToken, accessToken, globalAgentAccess, agentAccessEnabled. Pre-existing on main; #1290 added a targeted guard for linkedUserId only (the live-relay attribution identity). The general fix is a per-type allowlist of client-settable keys, with credential-class and privilege-class keys excluded by default.
🤖 Generated with Claude Code
https://claude.ai/code/session_013pc6nGXRS8mHvrwcXMSRDK
From sprint-review's #1290 pass:
{ ...currentConfig, ...config }(routes/integrations.ts) accepts any config key from any caller who passescanDeleteIntegration— includingbotToken,secretToken,accessToken,globalAgentAccess,agentAccessEnabled. Pre-existing on main; #1290 added a targeted guard forlinkedUserIdonly (the live-relay attribution identity). The general fix is a per-type allowlist of client-settable keys, with credential-class and privilege-class keys excluded by default.🤖 Generated with Claude Code
https://claude.ai/code/session_013pc6nGXRS8mHvrwcXMSRDK