T09 · Insecure Skill Coding Practices
- Location
src/utils/request.js:71- Finding
API credential exposed in URL query strings
- Content
View full analysis
Vulnerability Details
File Location:
src/utils/request.js:71-108; credential-bearing call sites includesrc/api/search.js:23-26,52-60,src/api/detail.js:20-23,46-51, andsrc/api/post.js:20-23,46-51
Vulnerability Type: Sensitive credential in URL query parameters
Risk Level: MediumComplete Code Snippet
javascript async function postJson(path, params, data) { if (!path || typeof path !== "string") { throw new Error("path 必须是非空字符串"); } if (!params || typeof params !== "object") { throw new Error("params 必须是对象"); } if (!data || typeof data !== "object") { throw new Error("data 必须是对象"); } const fullPath = `${path}?${querystring.stringify(params)}`; const jsonData = JSON.stringify(data); const options = { host: constants.BASE_URL, path: fullPath, method: "POST", headers: { "Content-Type": "application/json", "Content-Length": Buffer.byteLength(jsonData), }, }; return await request(options, jsonData); } async function getJson(path, params) { if (!path || typeof path !== "string") { throw new Error("path 必须是非空字符串"); } if (!params || typeof params !== "object") { throw new Error("params 必须是对象"); } params._ = Date.now(); const fullPath = `${path}?${querystring.stringify(params)}`; const options = { host: constants.BASE_URL, path: fullPath, method: "GET", headers: { "Content-Type": "application/json", }, }; return await request(options); }Credential-bearing parameters are supplied by each API module, for example:
javascript return await postJson( "/api/xiaohongshu/note-search/keyword", { _: Date.now(), token: token }, { keyword, type, sort, time, limit }, );javascript const res = await getJson("/api/xiaohongshu/note-search/info", { _: Date.now(), token: token, keyword, ...[truncated 1800 chars]- Remediation
View remediation
Remediation Suggestions
-
Remove the token from all query parameter objects.
-
Send the credential in an authorization header, preferably:
javascript headers: { "Authorization": `Bearer ${token}`, "Content-Type": "application/json" } -
If the upstream API cannot accept an authorization header, place the token in the HTTPS request body and ensure bodies are excluded from logs.
-
Configure the API server, reverse proxies, monitoring products, and web application firewalls to redact existing
tokenquery parameters. -
Rotate all tokens that may already have been captured in request logs.
-
Use short-lived, revocable, least-privilege credentials where supported.
-
Avoid echoing request URLs in diagnostics and add automated tests asserting that generated paths never contain
token=.
-
