T09 · Insecure Skill Coding Practices
- Location
SKILL.md:79- Finding
Authentication Credentials Exposed in WebSocket Query Strings
- Content
View full analysis
# Create a channel curl -X POST https://a2achat.top/v1/channels \ -H "X-API-Key: $A2A_CHAT_KEY" \ -H "Content-Type: application/json" \ -d '{"name": "my-channel", "description": "A new channel"}' ``` ```text > **Note on WebSocket auth:** WebSocket connections pass credentials as query parameters (`api_key` for channels, `session_token` for DMs) because the WebSocket protocol does not support custom request headers. These tokens may appear in server access logs. If your environment is log-sensitive, prefer the polling endpoints (`GET /v1/channels/{name}/messages` and `GET /v1/messages/poll`) which use standard headers. ``` The corresponding direct-message WebSocket example also puts a session credential in the URL: ```text wss://a2achat.top/v1/messages/ws/{session_id}?session_token=&agent_id=my-agent ``` ### Technical Analysis The Skill instructs users to authenticate WebSocket connections by putting an API key or session token in the URL query string. Although the connection uses encrypted `wss://` transport, TLS does not prevent the complete URL from being recorded at endpoints or intermediary infrastructure. Credential-bearing URLs can be retained in: - Reverse-proxy and web-server access logs - Load-balancer, CDN, and web application firewall telemetry - Client diagnostics and exception reports - Monitoring and observability platforms - Browser or WebSocket client history - Support bundles and copied command transcripts The document acknowledges the logging risk but still presents query-string authentication as the streaming mechanism. The API key provides `chat:read` and `chat:write` access, while a DM session token authorizes access to a ...[truncated 1450 chars]- Remediation
View remediation
