They used a heif payload to get server access but they never describe the SSO flaw they used to actually get repo access (the juicy part!), bummer!
Wish they shared that interesting piece since that's the interesting part.
Also pretty shocking that openai uses github. I would have expected a company of that size with that much to lose would be using self hosted stuff.
agreed… why can an ID token for a separate client application be used to read and write to GitHub? that’s the story here.