fix(security): remove accessToken from sessionStorage in OAuth flow state

The LiteLLM API key was being serialised into sessionStorage as part of
StoredFlowState. After the OAuth redirect the component re-mounts with the
same accessToken prop, so it never needed to be stored. Read it from props
in resumeOAuthFlow instead.
This commit is contained in:
Ishaan Jaffer 2026-03-10 20:56:30 -07:00
parent 170d6a3e56
commit 035c593999

View file

@ -54,7 +54,6 @@ type StoredFlowState = {
redirectUri: string;
clientId?: string;
clientSecret?: string;
accessToken: string;
scopes?: string[];
};
@ -175,7 +174,6 @@ export const useUserMcpOAuthFlow = ({
redirectUri,
clientId,
clientSecret,
accessToken,
scopes,
};
@ -240,7 +238,8 @@ export const useUserMcpOAuthFlow = ({
});
// Persist the token for this user via the backend.
await storeMCPOAuthUserCredential(flowState.accessToken, flowState.serverId, {
// accessToken comes from props — it is never stored in sessionStorage.
await storeMCPOAuthUserCredential(accessToken, flowState.serverId, {
access_token: token.access_token,
refresh_token: token.refresh_token,
expires_in: token.expires_in,
@ -260,7 +259,7 @@ export const useUserMcpOAuthFlow = ({
clearStorage(FLOW_STATE_KEY);
setTimeout(() => { processingRef.current = false; }, 1000);
}
}, [onSuccess]);
}, [accessToken, onSuccess]);
useEffect(() => {
resumeOAuthFlow();