T09 · Insecure Skill Coding Practices
- Location
scripts/publish.py:862- Finding
Custom API Base Can Receive WeChat Credentials, Access Tokens, and Unpublished Content
- Content
View full analysis
str: """获取 access_token(有效期 2 小时)。网络类失败会自动重试 1 次。""" url = ( f"{API_BASE}{API_PATH}/token?" f"grant_type=client_credential&appid={appid}&secret={appsecret}" ) data = _api_get(url) ``` ```python def _resolve_api_base(cfg: dict, slot: dict) -> str: """槽位 WECHAT_N_API_BASE 优先;为空时回退 config.yaml.wechat_api_base。""" slot_base = (slot.get("api_base") or "").strip() if slot_base: return _normalize_api_base(slot_base) cfg_base = str(cfg.get("wechat_api_base") or "").strip() if cfg_base: return _normalize_api_base(cfg_base) return "" def _init_api_base(): """优先用槽位 WECHAT_N_API_BASE;为空则回退 config.yaml.wechat_api_base。""" global API_BASE API_BASE = DEFAULT_API_BASE cfg = load_repo_config() env = _load_env_map() if not env: return slot_i = _slot_for_api_base(cfg, env) if slot_i is None: return slot = _active_slot_dict(cfg, env, slot_i) api_base = _resolve_api_base(cfg, slot) if not api_base: return API_BASE = api_base _info(f"API 端点: {API_BASE}{API_PATH}") def _get_token() -> str: _init_api_base() appid, appsecret = _get_credentials(_cli_account) return get_access_token(appid, appsecret) ``` The environment-check path also sends credentials to the configured endpoint: ```python api_base = _resolve_api_base(cfg, s) if api_base: API_BASE = api_base try: url = ( f"{API_BASE}{API_PATH}/token?" f"grant_type=client_credential&appid={s['appid']}&secret={s['appsecret']}" ) data = _api_get(url) ``` From `scrip ...[truncated 4192 chars]- Remediation
View remediation
