T09 · Insecure Skill Coding Practices
- Location
src/utils/request.js:76- Finding
API Credential Exposed Through URL Query Parameters
- Content
View full analysis
Vulnerability Details
File Location:
src/utils/request.js:76-119; credential parameters originate fromsrc/api/search.js:23-26,52-59,src/api/detail.js:20-23,46-50,src/api/comment.js:20-23,46-50, andsrc/api/post.js:20-23,46-50
Vulnerability Type: API credential exposure through URL query strings
Risk Level: MediumVulnerable Code
The API modules place the credential in the parameter object:
js return await postJson( "/api/xiaohongshu/note-search/keyword", { _: Date.now(), token: token }, { keyword, type, sort, time, limit }, );The request implementation serializes that object directly into the URL for both POST and GET requests:
js async function postJson(path, params, data) { if (!path || typeof path !== "string") { throw new Error("path must be a non-empty string"); } if (!params || typeof params !== "object") { throw new Error("params must be an object"); } if (!data || typeof data !== "object") { throw new Error("data must be an object"); } params.skill_name = skillName(); const fullPath = `${path}?${querystring.stringify(params)}`; const jsonData = JSON.stringify(data); const options = { host: constants.BASE_URL, path: fullPath, method: "POST", headers: { "Content-Type": "application/json", "Content-Length": Buffer.byteLength(jsonData), }, }; return await request(options, jsonData); } async function getJson(path, params) { if (!path || typeof path !== "string") { throw new Error("path must be a non-empty string"); } if (!params || typeof params !== "object") { throw new Error("params must be an object"); } params._ = Date.now(); const fullPath = `${path}?${querystring.stringify(params)}`; const options = { host: constants.BASE_URL, path: fullPath, method: "GET", headers: { "Content-Type": ...[truncated 2075 chars]- Remediation
View remediation
Remediation Suggestions
-
Remove
tokenfrom all query-parameter objects. -
Pass the credential through a dedicated request option and send it using an authorization header, such as:
js headers: { "Authorization": `Bearer ${token}`, "Content-Type": "application/json", } -
If the service uses a custom authentication scheme, use a dedicated secret header rather than a URL parameter.
-
Configure the API origin, reverse proxies, gateways, and telemetry systems to redact authorization headers and historical
tokenquery parameters. -
Rotate tokens that have already been used by the affected implementation.
-
Add automated tests asserting that generated request paths never contain
token=. -
Avoid including credentials in exception messages, debug output, metrics labels, or request tracing.
-
