T09 · Insecure Skill Coding Practices
- Location
scripts/twitter_oauth_client.py:384- Finding
Relay API Key Is Duplicated in Authorization Headers and Request Bodies
- Content
View full analysis
Dict[str, str]: headers = { "Authorization": f"Bearer {aisa_api_key}", "User-Agent": DEFAULT_CHROME_USER_AGENT, } if extra_headers: headers.update(extra_headers) return headers ``` The posting client then duplicates the same credential in the request body: ```python def post_single_tweet( config: Dict[str, Any], *, content: Optional[str] = None, media_ids: Optional[list[str]] = None, media_files: Optional[list[Dict[str, Any]]] = None, parent_tweet_id: Optional[str] = None, post_type: Optional[str] = None, ) -> Dict[str, Any]: payload: Dict[str, Any] = { "aisa_api_key": config["aisa_api_key"], } if content: payload["content"] = content if post_type: payload["type"] = post_type if media_ids: payload["media_ids"] = media_ids if parent_tweet_id: parent_key = "in_reply_to_tweet_id" if post_type == "reply" else "quote_tweet_id" payload[parent_key] = parent_tweet_id endpoint = f"{config['base_url']}/post_twitter" if media_files: return send_multipart_request( endpoint, payload, media_files, timeout=config["timeout"], ...[truncated 3004 chars]- Remediation
View remediation
