T09 · Insecure Skill Coding Practices
- Location
strategy_common.py:15- Finding
Unrestricted API Base URL Can Expose Credentials and Financial Account Data
- Content
View full analysis
requests.Session: session = requests.Session() session.headers.update({"X-API-KEY": MAXXIT_API_KEY, "Content-Type": "application/json"}) return session def api_get(session: requests.Session, path: str, params: Optional[Dict[str, Any]] = None) -> Optional[Dict[str, Any]]: url = f"{MAXXIT_API_URL}/api/lazy-trading/programmatic/{path}" try: response = session.get(url, params=params, timeout=REQUEST_TIMEOUT) response.raise_for_status() return response.json() except requests.RequestException as exc: log(f"GET {path} failed: {exc}") return None def api_post(session: requests.Session, path: str, payload: Dict[str, Any]) -> Optional[Dict[str, Any]]: url = f"{MAXXIT_API_URL}/api/lazy-trading/programmatic/{path}" try: response = session.post(url, json=payload, timeout=REQUEST_TIMEOUT) response.raise_for_status() return response.json() except requests.RequestException as exc: log(f"POST {path} failed: {exc}") return None ``` Equivalent unrestricted URL construction also occurs in: - `breakout-strategy.py:18-19, 62-69, 113-120` - `mean-reversion-strategy.py:18-19, 64-71, 118-125` - `taker-strategy.py:18-19, 72-90, 135-137` - `vwap-strategy.py:19, 61-68, 112-119` The shared behavior affects `ema-strategy.py`, `rsi-bollinger-strategy.py`, and `donchian-adx-strategy.py` through their use of `strategy_common.py`. ### Technical Analysis `MAXXIT_API_URL` is taken directly from the process environment and used as the destination for sessions containing `MAXXIT_API_KEY`. There is no validation that the destination: - Uses ...[truncated 2175 chars]- Remediation
View remediation
