T09 · Insecure Skill Coding Practices
- Location
btc_api.py:28- Finding
Unvalidated Path and Query Parameters Permit Request Manipulation
- Content
View full analysis
- Remediation
View remediation
MAX_LIMIT: raise ValueError("limit is outside the permitted range") query["limit"] = params elif isinstance(params, str): parsed = datetime.datetime.strptime(params, "%Y-%m-%d").date() query["date"] = parsed.isoformat() resp = requests.get(url, params=query, timeout=10) ``` 3. Validate dates with strict date parsing rather than checking whether the value contains a hyphen. 4. Require limits to be positive and impose a reasonable maximum. 5. Reject path separators, traversal sequences, control characters, and URL delimiters in field names. 6. If dynamic path components remain necessary, encode each component using `urllib.parse.quote(value, safe="")`. 7. Validate dictionary parameter keys against a small explicit allowlist before creating the request. 8. Enforce authorization independently on the internal API. The server must not rely on this client-side allowlist as a security boundary. ]]>
