Files
Dave HubbardandCursor f8ad1807cb verify: harden OAuth2 verification against credential leakage and silent failures
Three defensive fixes from Bugbot review:

1. SetOAuth2TokenSource disables cloud and found endpoints when a token
   source is set. OAuth2-authenticated requests carry a Bearer token and
   must only go to explicitly configured verification endpoints, never to
   native cloud APIs where the token could leak.

2. Add Attempted field to VerifyOutcome, set at the top of each loop
   iteration. When Attempted is true but Definitive is false, verification
   was configured but every endpoint failed (transport error, token
   acquisition failure). Callers now surface this as a verification error
   instead of silently reporting the secret as unverified.

3. Infer Content-Type from the body when no explicit header is set.
   Template-resolved bodies (always valid JSON) get application/json;
   raw secret bytes get text/plain. Prevents mislabeling non-JSON
   payloads as JSON in the engine path.

Co-authored-by: Cursor <[email protected]>
2026-09-17 17:51:47 -04:00
..
2026-09-10 12:18:33 -05:00
2026-09-10 12:18:33 -05:00
2026-02-20 11:03:16 -08:00
2024-09-26 10:17:47 -07:00