T09 · Insecure Skill Coding Practices
- Location
scripts/provider_sync.py:378- Finding
Stored Provider API Key Can Be Forwarded to an Arbitrary Endpoint
- Content
View full analysis
Tuple[str, Dict[str, str]]: """Resolve endpoint and Authorization header from config when possible. - If endpoint is empty, derive it from models.providers..baseUrl + '/models' - If Authorization header is missing and apiKey exists, add 'Authorization: Bearer ' NOTE: Do not print apiKey. """ provider_base = f"{provider_root}.{provider_id}" provider_obj = get_path(cfg, provider_base) or {} resolved_endpoint = (endpoint or "").strip() if not resolved_endpoint: base_url = (provider_obj.get("baseUrl") or "").strip() if not base_url: die(f"endpoint not provided and {provider_base}.baseUrl is missing") resolved_endpoint = base_url.rstrip("/") + "/models" # auth header api_key = provider_obj.get("apiKey") if isinstance(api_key, str) and api_key.strip(): if not get_header_case_insensitive(headers, "Authorization"): headers = dict(headers) headers["Authorization"] = f"Bearer {api_key.strip()}" return resolved_endpoint, headers ``` The resulting endpoint and headers are subsequently used in the outbound request: ```python headers = parse_headers(args.header) # Resolve endpoint + Authorization header from config when requested (or when endpoint omitted). if args.use_provider_config or not (args.endpoint or "").strip(): args.endpoint, headers = resolve_endpoint_and_auth_headers( cfg, args.provider_root, args.provider_id, args.endpoint, headers ) body = load_json(args.body_file) if args.bod ...[truncated 3287 chars]- Remediation
View remediation
