T09 · Insecure Skill Coding Practices
- Location
scripts/aqara_open_api.py:38- Finding
Authenticated API Requests Can Be Redirected to an Arbitrary Endpoint
- Content
View full analysis
str: """Resolve Open Platform REST base URL (no trailing slash).""" if explicit is not None and str(explicit).strip(): return str(explicit).strip().rstrip("/") env_url = (os.environ.get("AQARA_OPEN_API_URL") or "").strip() if env_url: return env_url.rstrip("/") disk_url = load_optional_open_api_base_url() if disk_url: return disk_url.rstrip("/") return _default_api_base_url() ``` The selected URL is subsequently used with the bearer credential: ```python self.api_key = key self.base_url = _resolve_api_base_url(api_base_url) self.session = requests.Session() self.session.headers.update({"application_id": "AqaraAgentSkills"}) self.session.headers.update({"Authorization": f"Bearer {key}"}) if home_id and str(home_id).strip(): self.session.headers.update({"position_id": str(home_id).strip()}) ``` The disk override is read from the credential file without validation: ```python def load_optional_open_api_base_url() -> Optional[str]: """ Optional full REST base URL from ``assets/user_account.json`` (e.g. local proxy). Tried in order: ``aqara_open_api_url``, ``open_api_url``. Whitespace-only values are ignored. """ _migrate_legacy_user_context_file() if not USER_ACCOUNT_PATH.exists(): return None try: data = json.loads(USER_ACCOUNT_PATH.read_text(encoding="utf-8")) if not isinstance(data, dict): return None for key in ("aqara_open_api_url", "open_api_url"): v = data.get(key) if isinstance(v, str) and v.strip(): return v.strip() return None ...[truncated 2225 chars]- Remediation
View remediation
