T09 · Insecure Skill Coding Practices
- Location
src/utils/request.js:76- Finding
API Token Exposed in URL Query Parameters
- Content
View full analysis
Vulnerability Details
File Location:
src/utils/request.js:76-119; token-bearing calls originate fromsrc/api/search.js:23-26, 52-55,src/api/comment.js:20-23, 46-49,src/api/detail.js:20-23, 46-49, andsrc/api/post.js:20-23, 46-49
Vulnerability Type: Authentication secret exposure through URL query strings
Risk Level: MediumVulnerable Code
javascript async function postJson(path, params, data) { if (!path || typeof path !== "string") { throw new Error("path 必须是非空字符串"); } if (!params || typeof params !== "object") { throw new Error("params 必须是对象"); } if (!data || typeof data !== "object") { throw new Error("data 必须是对象"); } params.skill_name = skillName(); const fullPath = `${path}?${querystring.stringify(params)}`; const jsonData = JSON.stringify(data); const options = { host: constants.BASE_URL, path: fullPath, method: "POST", headers: { "Content-Type": "application/json", "Content-Length": Buffer.byteLength(jsonData), }, }; return await request(options, jsonData); } async function getJson(path, params) { if (!path || typeof path !== "string") { throw new Error("path 必须是非空字符串"); } if (!params || typeof params !== "object") { throw new Error("params 必须是对象"); } params._ = Date.now(); const fullPath = `${path}?${querystring.stringify(params)}`; const options = { host: constants.BASE_URL, path: fullPath, method: "GET", headers: { "Content-Type": "application/json", }, }; return await request(options); }Representative token-bearing API call from
src/api/search.js:23-26:javascript return await postJson( "/api/xiaohongshu/note-search/keyword", { _: Date.now(), token: token }, { keyword, type, sort, time, limit }, );Representative token-bearing query request from
src/api/search.js:52-55:javascript const res = await getJson("/api/xiaohongshu/note-search/info", { _: Date.now() ...[truncated 1806 chars]- Remediation
View remediation
Remediation Suggestions
- Remove the token from all query parameter objects.
- Transmit it in an authentication header, for example:
javascript headers: { "Authorization": `Bearer ${token}`, "Content-Type": "application/json" }- Change
postJsonandgetJsonto accept authentication separately from ordinary query parameters. - Ensure server, proxy, telemetry, and error logs redact
Authorizationand any legacytokenparameters. - Rotate tokens that may already have appeared in access logs.
- Review and purge historical request logs according to the service's credential-retention policy.
- Add automated tests that fail if
token,api_key, or equivalent credential fields appear in generated request paths.
