📦

監査履歴

connector-googlemail - 1 監査

2026年7月23日 10:16

All 255 static findings are false positives caused by Markdown backticks, documented Google and Mops URLs, fixed relative links/imports, ellipses, and Gmail or OIDC terminology. Semantic review found unvalidated RFC 5322 headers and a disconnect flow that deletes local state without revoking Google's refresh token.

1
スキャンされたファイル
764
解析済み行数
5
レビュー項目
0
誤検知を無視

確認済みのセキュリティ上の懸念 (2)

高
RFC 5322 Header Injection
The sample concatenates `to` and `subject` directly into RFC 5322 headers. Newlines can inject headers, add recipients, or alter message structure.
Lines 390-392 show direct concatenation with no CR or LF validation before the message is sent.
中
Disconnect Does Not Revoke Google Token
The disconnect endpoint removes the map entry without revoking the Google refresh token. A previously exposed token remains usable after users disconnect.
Lines 303-307 only remove local state and contain no Google token revocation call.
監査者: codex