T09 · Insecure Skill Coding Practices
- Location
src/utils/request.js:76- Finding
API Credential Exposed in HTTP Query Strings
- Content
View full analysis
Vulnerability Details
File Location:
src/utils/request.js:76-98; credential-bearing calls originate fromsrc/api/search.js:20-28,49-59,src/api/detail.js:17-25,43-50,src/api/comment.js:17-24,43-49, andsrc/api/post.js:17-24,43-49
Vulnerability Type: API credential exposure through URL query parameters
Risk Level: MediumVulnerable Code
src/api/search.js:20-28:js async function createSearchTask(token, keyword, type, sort, time, limit) { return await withRetry( async () => { return await postJson( "/api/xiaohongshu/note-search/keyword", { _: Date.now(), token: token }, { keyword, type, sort, time, limit }, ); },src/api/search.js:49-59:js async function getSearchTask(token, keyword, type, sort, time, limit) { return await withRetry( async () => { const res = await getJson("/api/xiaohongshu/note-search/info", { _: Date.now(), token: token, keyword, type, sort, time, limit, });src/utils/request.js:76-98:js async function postJson(path, params, data) { if (!path || typeof path !== "string") { throw new Error("path 必须是非空字符串"); } if (!params || typeof params !== "object") { throw new Error("params 必须是对象"); } if (!data || typeof data !== "object") { throw new Error("data 必须是对象"); } params.skill_name = skillName(); const fullPath = `${path}?${querystring.stringify(params)}`; const jsonData = JSON.stringify(data); const options = { host: constants.BASE_URL, path: fullPath, method: "POST", headers: { "Content-Type": "application/json", "Content-Length": Buffer.byteLength(jsonData), }, }; return await request(options, jsonData); }src/utils/request.js:101-119:js async function getJson(path, para ...[truncated 2795 chars]- Remediation
View remediation
Remediation Suggestions
-
Remove
tokenfrom every query-parameter object. -
Transmit the credential in a dedicated header, preferably:
js headers: { "Authorization": `Bearer ${token}`, "Content-Type": "application/json", } -
Refactor
postJson()andgetJson()to accept the token separately from ordinary query parameters, preventing accidental future serialization. -
Configure API servers, reverse proxies, monitoring platforms, and error-reporting systems to redact authentication headers and sensitive query parameters.
-
Avoid including complete request URLs in exceptions, traces, or debug logs.
-
Rotate credentials that may already have appeared in access or observability logs.
-
Add automated tests asserting that generated request paths never contain
token,secret, or authorization values.
-
