T09 · Insecure Skill Coding Practices
- Location
scripts/caldav.js:152- Finding
Basic Authentication Credentials Can Be Sent to Insecure or Untrusted DAV Endpoints
- Content
View full analysis
(typeof c === 'string' ? c.toUpperCase() : '') === 'VTODO'); } if (_vtodoSupportCache.has(calendar.url)) { return _vtodoSupportCache.get(calendar.url); } try { const encoded = Buffer.from(`${config.username}:${config.password}`).toString('base64'); const resp = await fetch(calendar.url, { method: 'PROPFIND', headers: { Authorization: `Basic ${encoded}`, ``` ```javascript // scripts/caldav.js:152-158 async function davPut(url ...[truncated 2920 chars]- Remediation
View remediation
