T09 · Insecure Skill Coding Practices
- Location
send.js:25- Finding
Feishu Tenant Access Token Stored in an Unprotected Plaintext File
- Content
View full analysis
now + 60) { return cached.token; } } catch (e) {} } if (forceRefresh) { try { if (fs.existsSync(TOKEN_CACHE_FILE)) fs.unlinkSync(TOKEN_CACHE_FILE); } catch(e) {} } try { const res = await fetch('https://open.feishu.cn/open-apis/auth/v3/tenant_access_token/internal', { method: 'POST', headers: { 'Content-Type': 'application/json' }, body: JSON.stringify({ app_id: APP_ID, app_secret: APP_SECRET }) }); const data = await res.json(); if (data.code !== 0) throw new Error(`API Error: ${data.msg}`); // 2. Update Memory Cache (File) try { const cacheData = { token: data.tenant_access_token, expire: now + data.expire }; const cacheDir = path.dirname(TOKEN_CACHE_FILE); if (!fs.existsSync(cacheDir)) fs.mkdirSync(cacheDir, { recursive: true }); fs.writeFileSync(TOKEN_CACHE_FILE, JSON.stringify(cacheData, null, 2)); } catch (e) { console.error("Failed to write token cache:", e.message); } return data.tenant_access_token; ``` ### Technical Analysis The Skill legitimately submits `FEISHU_APP_ID` and `FEISHU_APP_SECRET` to Feishu's official tenant-token endpoint because authentication is required to ...[truncated 1934 chars]- Remediation
View remediation
