T09 · Insecure Skill Coding Practices
- Location
src/utils/request.js:86- Finding
Raw API Token Transmitted in URL Query Strings
- Content
View full analysis
Vulnerability Details
File Location:
src/utils/request.js:86-96,src/utils/request.js:108-117; token parameters originate fromsrc/api/search.js:23-26,52-55,src/api/comment.js:20-23,46-49,src/api/detail.js:20-23,46-49, andsrc/api/post.js:20-23,46-49
Vulnerability Type: Credential exposure through URL query parameters
Risk Level: MediumVulnerable Code
src/api/search.js:23-27:js return await postJson( "/api/xiaohongshu/note-search/keyword", { _: Date.now(), token: token }, { keyword, type, sort, time, limit }, );src/api/search.js:52-60:js const res = await getJson("/api/xiaohongshu/note-search/info", { _: Date.now(), token: token, keyword, type, sort, time, limit, });src/utils/request.js:86-96:js params.skill_name = skillName(); const fullPath = `${path}?${querystring.stringify(params)}`; const jsonData = JSON.stringify(data); const options = { host: constants.BASE_URL, path: fullPath, method: "POST", headers: { "Content-Type": "application/json", "Content-Length": Buffer.byteLength(jsonData), }, };src/utils/request.js:108-117:js params._ = Date.now(); const fullPath = `${path}?${querystring.stringify(params)}`; const options = { host: constants.BASE_URL, path: fullPath, method: "GET", headers: { "Content-Type": "application/json", }, };Technical Analysis
The API modules pass the raw
GUAIKEI_API_TOKENas a member of theparamsobject. The request utility serializes all parameters withquerystring.stringify()and appends them directly to the request path. The same pattern is used by all four supported operations.The token validation function does not derive a temporary credential or otherwise transform the secret;
src/utils/key.jsreturns the supplied token unchanged. Consequently, the original API cred ...[truncated 1512 chars]- Remediation
View remediation
Remediation Suggestions
-
Remove the token from all query-parameter objects.
-
Transmit it in an HTTP authorization header, for example:
js headers: { "Authorization": `Bearer ${token}`, "Content-Type": "application/json", } -
Refactor
postJson()andgetJson()to accept the token separately from ordinary request parameters so callers cannot accidentally serialize credentials into URLs. -
Ensure server, proxy, and application logs redact authorization headers and any legacy
tokenquery parameter. -
Rotate tokens that may already have appeared in infrastructure logs.
-
Add automated tests asserting that generated request paths never contain
token,api_key,authorization, or the configured credential value. -
Prefer short-lived, narrowly scoped credentials where supported.
-
