T09 · Insecure Skill Coding Practices
- Location
src/api/search.js:20- Finding
API Credential Transmitted in URL Query Strings
- Content
View full analysis
Vulnerability Details
File Location:
src/api/search.js:20-28,src/api/search.js:49-60,src/api/detail.js:17-25,src/api/detail.js:43-52,src/api/comment.js:17-25,src/api/comment.js:43-52,src/api/post.js:17-25,src/api/post.js:43-52, andsrc/utils/request.js:85-90
Vulnerability Type: API credential exposure through query parameters
Risk Level: MediumVulnerable Code
The search task creation endpoint passes the API credential as a query parameter:
js async function createSearchTask(token, keyword, type, sort, time, limit) { return await withRetry( async () => { return await postJson( "/api/xiaohongshu/note-search/keyword", { _: Date.now(), token: token }, { keyword, type, sort, time, limit }, ); }, constants.CREATE_MAX_ATTEMPTS, (attempt, err) => { utils.printError( `【创建任务重试】 ${attempt + 1}/${constants.CREATE_MAX_ATTEMPTS} 次 - ${err.message}`, ); }, ); }The polling endpoint handles the credential in the same manner:
js const res = await getJson("/api/xiaohongshu/note-search/info", { _: Date.now(), token: token, keyword, type, sort, time, limit, });Equivalent query-parameter credential handling occurs in the detail, comment, and post API modules:
js return await postJson( "/api/xiaohongshu/detail/url", { _: Date.now(), token: token }, { url: url, limit: limit }, );js const res = await getJson("/api/xiaohongshu/comment/info", { _: Date.now(), token: token, url, limit, });js const res = await getJson("/api/xiaohongshu/post/info", { _: Date.now(), token: token, url, limit, });The request utility serializes these parameters directly into the request URL:
js params.skill_name = skillName(); const fullPath = `${path}?${querystring.stringify ...[truncated 2114 chars]- Remediation
View remediation
Remediation Suggestions
-
Remove
tokenfrom all query-parameter objects. -
Send the credential through a dedicated authorization header, for example:
js headers: { "Authorization": `Bearer ${token}`, "Content-Type": "application/json", } -
Refactor
postJsonandgetJsonto accept authentication separately from ordinary request parameters. -
Ensure request logging, error reporting, and telemetry redact
Authorization, cookies, tokens, and other secrets. -
Configure the API gateway and origin server not to record authentication material.
-
Rotate credentials that have already been used by this implementation because they may exist in historical logs.
-
Prefer short-lived, narrowly scoped tokens and enforce rate limits to reduce the impact of credential reuse.
-
