AGENTFORCE-SEC-04: Connected App With Full / Non-Expiring OAuth Access
๐ก Medium ยท Credential Exposure
Detects connected apps and External Client Apps that grant the Full OAuth scope or the RefreshToken scope with refresh tokens that never expire, and client-credentials apps whose consumer secret is optional. Also lists PKCE disabled on public clients, relaxed IP restrictions and System Administrator pre-authorization. High for a Full-scope client-credentials app that also skips its secret or never expires refresh tokens; medium for Full combined with non-expiring refresh tokens or client credentials, a client-credentials app with an optional secret, or a non-expiring refresh token on a weak client; low for Full alone or a non-expiring refresh token alone.
Detailsโ
| Field | Value |
|---|---|
| Rule ID | AGENTFORCE-SEC-04 |
| Severity | Medium |
| Category | Credential Exposure |
| Compliance | SOC2_CC6, PCI_DSS |
Remediationโ
Request only the scopes the integration uses (api, not full; drop refresh_token unless offline access is needed), set the refresh token policy to expire (e.g. 'Expire refresh token after' a fixed period or when unused) with rotation, require the consumer secret and PKCE, keep IP restrictions enforced, and pre-authorize a dedicated integration permission set instead of System Administrator.