T09 · Insecure Skill Coding Practices
- Location
scripts/tickflow_common.py:69- Finding
API Key Disclosure Through an Unrestricted Network Destination
- Content
View full analysis
dict: params = { "symbol": args.symbol, "period": args.period, "count": args.count, "start_time": args.start_time, "end_time": args.end_time, "adjust": args.adjust, } payload = request_json( "GET", "/v1/klines", api_key, base_url=args.base_url, params=params, timeout=args.timeout, ) payload = ensure_dict(payload, name="response") payload["data ...[truncated 4315 chars]- Remediation
View remediation
str: parsed = urlparse(value) if parsed.scheme != "https": raise TickFlowError("The API endpoint must use HTTPS.") if parsed.hostname != "api.tickflow.org": raise TickFlowError("Unapproved TickFlow API hostname.") if parsed.username or parsed.password: raise TickFlowError("Embedded URL credentials are not allowed.") if parsed.port not in (None, 443): raise TickFlowError("Unapproved API endpoint port.") return "https://api.tickflow.org" ``` 3. **Separate production and test authentication** If custom endpoints are needed for testing, require an explicit development mode and use a non-production test credential. Production `TICKFLOW_API_KEY` values should never be attached to arbitrary test servers. 4. **Restrict redirect behavior** Reject cross-origin redirects for authenticated requests. Do not forward `x-api-key` when the redirect changes the scheme, hostname, or port. 5. **Enforce TLS** Reject plaintext HTTP even in development unless a clearly isolated test credential is used. Certificate verification should remain enabled. 6. **Rotate potentially exposed credentials** If the scripts have previously been run with untrusted `--base-url` values, revoke and rotate the affected TickFlow API keys and review API usage logs for unauthorized activity. 7. **Add securi ...[truncated 317 chars]
