T09 · Insecure Skill Coding Practices
- Location
scripts/x402_request.py:130- Finding
Untrusted x402 endpoint controls critical signed authorization fields
- Content
View full analysis
str: """Sign an EIP-712 TransferWithAuthorization and return base64 payment payload.""" now = int(time.time()) nonce = "0x" + os.urandom(32).hex() chain_id = int(accepted["network"].split(":")[1]) amount_atomic = int(accepted.get("maxAmountRequired") or accepted["amount"]) authorization = { "from": wallet_address, "to": accepted["payTo"], "value": amount_atomic, "validAfter": now - 60, "validBefore": now + accepted["maxTimeoutSeconds"], "nonce": nonce, } structured_data = { "types": { "EIP712Domain": [ {"name": "name", "type": "string"}, {"name": "version", "type": "string"}, {"name": "chainId", "type": "uint256"}, {"name": "verifyingContract", "type": "address"}, ], "TransferWithAuthorization": [ {"name": "from", "type": "address"}, {"name": "to", "type": "address"}, {"name": "value", "type": "uint256"}, {"name": "validAfter", "type": "uint256"}, {"name": "validBefore", "type": "uint256"}, {"name": "nonce", "type": "bytes32"}, ], }, "domain": { "name": accepted["extra"]["name"], "version": accepted["extra"]["version"], "chainId": chain_id, "verifyingContract": accepted["asset"], }, "primaryType": "TransferWithAuthorization", "message": authorization, } msg = encode_typed_data(full_messa ...[truncated 3041 chars]- Remediation
View remediation
