🚨 Severity: HIGH 💡 Vulnerability: User-provided IMAP `host` in `_test_imap_connection` and `pull_inbox` was not validated against private IPs, creating an SSRF risk. 🎯 Impact: Attackers could abuse the endpoints to port-scan or interact with internal/private network services. 🔧 Fix: Integrated `is_private_ip` from `app.utils.network` to block connections resolving to private, loopback, link-local, or reserved IPs. ✅ Verification: Ran `test_imap_tasks.py` and `test_api_imap_accounts.py` successfully. Checked `ruff` output and diffs. Removed all scratch files from the commit. Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
6.2 KiB
Setting up Dropbox Integration
This guide explains how to set up the Dropbox integration for DocuElevate.
Required Configuration Parameters
| Variable | Description |
|---|---|
DROPBOX_APP_KEY |
Dropbox API app key |
DROPBOX_APP_SECRET |
Dropbox API app secret |
DROPBOX_REFRESH_TOKEN |
OAuth2 refresh token for Dropbox |
DROPBOX_FOLDER |
Default folder path for Dropbox uploads |
For a complete list of configuration options, see the Configuration Guide.
Setup Methods
DocuElevate supports two distinct Dropbox OAuth flows:
- Per-User Integration Wizard (Recommended for end users): Triggered from the Integrations dashboard (
/integrations) by clicking Authorize on a Dropbox destination or Dropbox-backed Watch Folder. Credentials are saved securely to your personal integration record — global settings are never exposed. - System-Level Setup Wizard: Available at
/dropbox-setupfor administrators configuring the global system-wide Dropbox connection. Generates environment variables for all worker nodes. - Manual Setup: Following the step-by-step instructions in this document.
Per-User OAuth Flow (Integrations Dashboard)
End users authorize their own Dropbox integration from the Integrations dashboard:
- Navigate to
/integrationsand click + Add Destination (or + Add Source for Watch Folder). - Create a Dropbox destination integration (or a Watch Folder with
source_type = dropbox). - Click the Authorize button next to the integration — it links directly to the OAuth wizard pre-loaded with your integration's configuration.
- Enter your Dropbox App Key and App Secret in the wizard (or use the global admin credentials if pre-configured).
- Click Start Authentication Flow, authorize access in Dropbox, and the refresh token is automatically saved to your personal integration record.
- The page redirects back to
/integrationson success. Re-authorization is available at any time via the Re-Authorize button.
Note: Your credentials are stored encrypted per-integration and are never mixed with other users' data. Each user can have multiple Dropbox integrations with independent tokens.
Using the System-Level Setup Wizard (Admin)
The easiest way to configure the global Dropbox integration is to use the built-in setup wizard:
- Navigate to the
/dropbox-setuppage in your DocuElevate instance. - Follow the on-screen instructions to create a Dropbox app.
- Enter your App Key and App Secret in the wizard.
- Optionally specify a custom folder path for uploads.
- Click Start Authentication Flow to begin the authorization process.
- Complete the Dropbox authentication process.
- The system will automatically exchange the authorization code for a refresh token.
- Copy the generated environment variables for your worker nodes.
The wizard handles all the token exchange steps and provides you with the exact configuration needed for your environment.
Step-by-Step Manual Setup Instructions
1. Create a Dropbox App
- Go to the Dropbox Developer Apps Console
- Click "Create app"
- Select "Scoped access" for API
- Choose "Full Dropbox" access (or "App folder" for more restricted access)
- Give your app a name (e.g., "DocuElevate")
- Click "Create app"
2. Configure App Permissions
- In your app's settings page, go to the "Permissions" tab
- Enable the following permissions:
files.content.write(to upload files)files.content.read(if you need to read file content)
- Click "Submit" to save changes
3. Get App Key and Secret
- On your app's settings page, find the "App key" and "App secret"
- Set these as
DROPBOX_APP_KEYandDROPBOX_APP_SECRETin your configuration
4. Generate a Refresh Token
-
Go to the "OAuth 2" tab in your app settings
-
Add a redirect URI:
http://localhost(this is for the authorization flow) -
Generate an authorization URL with these instructions:
https://www.dropbox.com/oauth2/authorize?client_id=YOUR_APP_KEY&response_type=code&token_access_type=offline -
Replace
YOUR_APP_KEYwith your app key -
Open this URL in your browser
-
Authorize the app when prompted
-
You'll be redirected to
localhostwith a code parameter in the URL -
Copy this code parameter
5. Exchange the Code for a Refresh Token
-
Use this curl command to exchange the code for tokens:
curl -X POST https://api.dropboxapi.com/oauth2/token \ -d code=YOUR_AUTH_CODE \ -d grant_type=authorization_code \ -d client_id=YOUR_APP_KEY \ -d client_secret=YOUR_APP_SECRET \ -d redirect_uri=http://localhost -
From the response, copy the
refresh_tokenvalue
6. Configure DocuElevate
- Set
DROPBOX_APP_KEY,DROPBOX_APP_SECRET, andDROPBOX_REFRESH_TOKENwith your values - Set
DROPBOX_FOLDERto the path where files should be uploaded (e.g.,/Documents/Uploads)
Token Management
The system will use the refresh token to automatically generate short-lived access tokens when needed. Refresh tokens typically don't expire unless revoked.
Testing Your Token
You can test if your token is working correctly:
- Navigate to the
/dropbox-setuppage in your DocuElevate instance - Click the "Test Token" button to verify your credentials
- If the test fails, click "Refresh Token" to obtain a new refresh token
Troubleshooting
If you encounter issues with Dropbox integration:
- Authentication Errors: Make sure your App Key and App Secret are correct
- Token Expired: Click "Refresh Token" button on the setup page to obtain a new token
- Folder Permissions: Ensure your app has the correct permissions enabled for file operations
- Invalid Redirect URI: Verify that the redirect URI in your app settings matches the one used in the authentication flow
- Rate Limiting: Dropbox API has rate limits; if exceeded, wait and try again
For more general configuration issues, see the Configuration Troubleshooting Guide.