T09 · Insecure Skill Coding Practices
- Location
scripts/dashboard_server.py:48- Finding
Unauthenticated Disclosure of Planner Data over LAN and Public Tunnels
- Content
View full analysis
None: """Route GET requests to the appropriate handler.""" parsed = urlparse(self.path) path = parsed.path if path.startswith("/api/"): self._handle_api(path, parsed.query) else: # Serve static files from the dashboard directory super().do_GET() def _handle_api(self, path: str, query_string: str) -> None: """Dispatch API requests.""" params = parse_qs(query_string) routes: dict[str, Any] = { "/api/stats": self._api_stats, "/api/projects": self._api_projects, "/api/tasks": self._api_tasks, "/api/search": self._api_search, "/api/due-soon": self._api_due_soon, "/api/overdue": self._api_overdue, "/api/health": self._api_health, } if path.startswith("/api/attachment/"): parts = path.split("/api/attachment/")[1].strip("/").split("/", 1) if len(parts) == 2: self._api_serve_attachment(unquote(parts[0]), unquote(parts[1])) else: self._json_response({"error": "Bad attachment path"}, status=400) return if path.startswith("/api/project/"): project_id = path.split("/api/project/")[1].strip("/") self._api_single_project(project_id) return if path.startswith("/api/task/"): task_id = path.split("/api/task/")[1].strip("/") self._api_single_task(task_id) return ``` ```python host = "0.0.0.0" if allow_network else "127.0.0.1" # ... _server = HTTPServer((host, actual_port), handler) ``` The same unauthenticated server can be made publicly reachable through the tunnel integration: ```python def _start_clo ...[truncated 2592 chars]- Remediation
View remediation
