T09 · Insecure Skill Coding Practices
- Location
src/api/comment.js:17- Finding
API Credential Transmitted in URL Query Strings
- Content
View full analysis
{ return await postJson( "/api/xiaohongshu/comment/url", { _: Date.now(), token: token }, { url, limit }, ); }, ``` Polling requests expose the same credential: ```js async function getCommentTask(token, url, limit) { return await withRetry( async () => { const res = await getJson("/api/xiaohongshu/comment/info", { _: Date.now(), token: token, url, limit, }); ``` The shared request implementation serializes those parameters directly into the URL: ```js async function postJson(path, params, data) { if (!path || typeof path !== "string") { throw new Error("path must be a non-empty string"); } if (!params || typeof params !== "object") { throw new Error("params must be an object"); } if (!data || typeof data !== "object") { throw new Error("data must be an object"); } params.skill_name = skillName(); const fullPath = `${path}?${querystring.stringify(params)}`; const jsonData = JSON.stringify(data); const options = { host: constants.BASE_URL, path: fullPath, method: "POST", headers: { "Content-Type": "application/json", "Content-Length": Buffer.byteLength(jsonData), }, }; return await request(options, jsonData); } ``` ```js async function getJson(path, params) { if (!path || typeof path !== "string") { throw new Error("path must be a non-empty string"); } if (!params || typeof params !== "object ...[truncated 2304 chars]- Remediation
View remediation
