T09 · Insecure Skill Coding Practices
- Location
scripts/configure.py:65- Finding
Bearer API Key and User-Supplied Images Can Be Transmitted over Plaintext HTTP
- Content
View full analysis
dict: api_key = str(config.get("api_key", "")).strip() base_url = str(config.get("base_url", "")).strip().rstrip("/") if not api_key.startswith("lgz_"): raise SystemExit("Invalid Lingzao API key. It should start with lgz_.") if not base_url.startswith(("http://", "https://")): raise SystemExit("Invalid Lingzao base URL. It should start with http:// or https://.") return {"api_key": api_key, "base_url": base_url} ``` ```python # scripts/lingzao_client.py:894-917 def request_json( config: dict, method: str, path: str, body: Optional[Dict[str, Any]] = None, timeout: int = DEFAULT_TIMEOUT, headers: Optional[Dict[str, str]] = None, ) -> Dict[str, Any]: url = config["base_url"] + path data = None request_headers = { "accept": "application/json", "authorization": f"Bearer {config['api_key']}", } if headers: request_headers.update(headers) if body is not None: data = json.dumps(body, ensure_ascii=False).encode("utf-8") request_headers["content-type"] = "application/json" request = urllib.request.Request(url, data=data, headers=request_headers, method=method) try: record_timeout_probe(method, path, timeout) with urllib.request.urlopen(request, timeout=timeout) as response: return parse_json_response(response.read()) ``` ```python # scripts/lingzao_client.py:935-948 def request_multipart( config: dict, method: str, path: str, fields: Dict[s ...[truncated 3951 chars]- Remediation
View remediation
