T09 · Insecure Skill Coding Practices
- Location
src/utils/request.js:76- Finding
API Credential Exposed in URL Query Strings
- Content
View full analysis
Vulnerability Details
File Locations:
src/utils/request.js:76-96src/utils/request.js:101-117src/api/search.js:23-26src/api/search.js:52-59src/api/detail.js:20-23src/api/detail.js:46-50src/api/comment.js:20-23src/api/comment.js:46-50src/api/post.js:20-23src/api/post.js:46-50
Vulnerability Type: Sensitive credential exposure through URL query parameters
Risk Level: MediumVulnerable Code
The API modules include the credential in the request parameter object. For example, task creation in
src/api/search.js:23-26uses:js return await postJson( "/api/xiaohongshu/note-search/keyword", { _: Date.now(), token: token }, { keyword, type, sort, time, limit }, );Task polling in
src/api/search.js:52-59also includes the token:js const res = await getJson("/api/xiaohongshu/note-search/info", { _: Date.now(), token: token, keyword, type, sort, time, limit, });The same pattern appears in the detail, comment, and post API modules:
js // src/api/detail.js { _: Date.now(), token: token } // src/api/comment.js { _: Date.now(), token: token } // src/api/post.js { _: Date.now(), token: token }The request utility serializes these parameter objects directly into the URL. The complete relevant POST request construction in
src/utils/request.js:76-96is:js async function postJson(path, params, data) { if (!path || typeof path !== "string") { throw new Error("path 必须是非空字符串"); } if (!params || typeof params !== "object") { throw new Error("params 必须是对象"); } if (!data || typeof data !== "object") { throw new Error("data 必须是对象"); } params.skill_name = skillName(); const fullPath = `${path}?${querystring.stringify(params)}`; const jsonData = JSON.stringify(data); const options = { host: constants.BASE_URL, ...[truncated 3316 chars]- Remediation
View remediation
Remediation Suggestions
-
Remove
tokenfrom every query parameter object in:src/api/search.jssrc/api/detail.jssrc/api/comment.jssrc/api/post.js
-
Pass credentials through an HTTP authorization header, preferably:
js headers: { "Authorization": `Bearer ${token}`, "Content-Type": "application/json", }Refactor
getJsonandpostJsonto accept the token separately from ordinary request parameters so that callers cannot accidentally serialize it into the URL. -
If the remote API cannot accept bearer authentication, place the token in the HTTPS POST body for task creation and redesign polling authentication accordingly. Header-based authentication remains preferable.
-
Configure the API server, reverse proxies, gateways, and observability platforms to redact:
Authorizationheaders- Existing
tokenquery parameters - Any other authentication or session values
-
Rotate all tokens that may have already appeared in URL logs. Purge or restrict historical logs containing query strings according to the applicable retention policy.
-
Add automated tests asserting that generated request paths never contain
token=,api_key=, or equivalent credential parameters. -
Apply short token lifetimes, least-privilege authorization, server-side rate limits, usage monitoring, and immediate revocation support to reduce the impact of future credential exposure.
-
