• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

loopbackio / loopback-next / 38002056331
56%

Build:
DEFAULT BRANCH: master
Ran 09 Oct 2026 11:25PM UTC
Jobs 0
Files 0
Run time –
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

pending completion
  cancel
38002056331

push

github

dhmlau
fix(mock-oauth2-provider): resolve CodeQL prototype pollution and open redirect

Registered apps and issued tokens were held in plain objects keyed by values
taken from the request, so a `__proto__` key reached `Object.prototype`. They
are `Map`s now, which also drops the `[key: string]: any` index signature from
the `App` interface (CodeQL js/prototype-polluting-assignment).

`redirect_uri` is validated before a token is issued and the callback url is
built from the parsed `URL` rather than by concatenating the request value. A
real authorization server matches `redirect_uri` against the callback urls
registered for the client; this provider only ever serves test applications
running on the same machine, so it accepts loopback hosts
(CodeQL js/server-side-unvalidated-url-redirection).

The async route handlers are wrapped so that rejections reach Express instead
of becoming unhandled promise rejections.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Raymond Feng <enjoyjava@gmail.com>
Source Files on build 38002056331
Detailed source file information is not available for this build.
  • Back to Repo
  • Github Actions Build #38002056331
  • f798d83c on github
  • Prev Build on master (#38002002441)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc