T09 · Insecure Skill Coding Practices
- Location
fetch_topics.js:23- Finding
Hardcoded Access Token and Insecure Plaintext Credential Fallback
- Content
View full analysis
persistent file > default token if (process.env.ZSXQ_TOKEN) { return process.env.ZSXQ_TOKEN; } // Attempt to read from a file try { if (fs.existsSync(TOKEN_FILE)) { const data = JSON.parse(fs.readFileSync(TOKEN_FILE, 'utf-8')); if (data.token && data.token.trim()) { console.error('[zsxq] loaded token from token.json'); return data.token; } } } catch (err) { console.error(`[zsxq] failed to load token file: ${err.message}`); } // Use the default token console.error('[zsxq] using default persisted token'); return DEFAULT_TOKEN; } function saveToken(token) { try { fs.writeFileSync( TOKEN_FILE, JSON.stringify({ token, updated_at: new Date().toISOString() }, null, 2), 'utf-8' ); console.error('[zsxq] token saved to token.json'); } catch (err) { console.error(`[zsxq] failed to save token: ${err.message}`); } } ``` The selected credential is then placed in an authentication cookie: ```js const ZSXQ_TOKEN = loadToken(); if (!ZSXQ_TOKEN) { console.error(JSON.stringify({ error: 'ZSXQ_TOKEN not configured' })); process.exit(1); } const BASE_URL = 'https://api.zsxq.com/v2'; const HEADERS = { 'Cookie': `zsxq_access_token=${ZSXQ_TOKEN}`, 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36', 'Origin': 'https://wx.zsxq.com', 'Referer': 'https://wx.zsxq.com/', 'Accept': 'application/json', 'X-Timestamp': String(Math.floor(Da ...[truncated 2902 chars]- Remediation
View remediation
