docs(pi): add integration docs and example - #5796
eersnington wants to merge 2 commits into
Conversation
4f4fcc4 to
b004815
Compare
|
Code Review Reviewed the current diff. The 1. Scripts run 2. Missing pieces required by
3. 4. Security and robustness
5. Other
🤖 Generated with Claude Code |
e5040f4 to
89a5bd7
Compare
| withoutRefreshToken(c.state.saved[provider]), | ||
| refresh: async (c, provider: string) => { |
There was a problem hiding this comment.
🟠 Medium · Credential actions expose provider tokens to every caller
read returns the stored API key or OAuth access token, and save also lets an unauthenticated caller replace it. Because this actor has no connection or action authorization, anyone who can reach it and select a user's actor key can steal or overwrite that user's login; the README warning does not enforce the boundary. Make the credential store inaccessible to public actor clients, or add authentication and actor-key authorization to the example before exposing these actions.
dc9d5b1 to
3e2a18d
Compare
b004815 to
1e7248d
Compare
3e2a18d to
4a970f3
Compare
1e7248d to
1448347
Compare
3f92a6f to
b2d96c4
Compare
1448347 to
5719ca6
Compare
b2d96c4 to
04872eb
Compare
5719ca6 to
ff2b289
Compare
Adds the Pi page at
/integrations/pi, its quickstart snippets, andexamples/pi-credentials.credentialsbacked by acredentialsactor.examples/pi-credentials: acredentialsactor that stores and refreshes each user's logins, andpnpm provider-loginto try it.This is part 3 of 3 in a stack: