T09 · Insecure Skill Coding Practices
- Location
src/utils/request.js:78- Finding
API Credential Exposed Through URL Query Parameters
- Content
View full analysis
{ return await postJson( "/api/xiaohongshu/note-search/keyword", { _: Date.now(), token: token }, { keyword, type, sort, time, limit }, ); }, ``` From `src/api/search.js:49-60`: ```js async function getSearchTask(token, keyword, type, sort, time, limit) { return await withRetry( async () => { const res = await getJson("/api/xiaohongshu/note-search/info", { _: Date.now(), token: token, keyword, type, sort, time, limit, }); ``` From `src/utils/request.js:73-79`: ```js async function postJson(path, params, data) { if (!path || typeof path !== "string") { throw new Error("path must be a non-empty string"); } if (!params || typeof params !== "object") { throw new Error("params must be an object"); } if (!data || typeof data !== "object") { throw new Error("data must be an object"); } params.skill_name = skillName(); const fullPath = `${path}?${querystring.stringify(params)}`; ``` From `src/utils/request.js:98-104`: ```js async function getJson(path, params) { if (!path || typeof path !== "string") { throw new Error("path must be a non-empty string"); } if (!params || typeof params !== "object") { throw new Error("params must be an object"); } params._ = Date.now(); const fullPath = `${path}?${querystring.stringify(params)}`; ``` The same credential-bearing param ...[truncated 2233 chars]- Remediation
View remediation
