T09 · Insecure Skill Coding Practices
- Location
src/quark_lazy_cli/api.py:86- Finding
QAS Authentication Token Exposed Through URL Query Parameters and Plaintext HTTP
- Content
View full analysis
dict: """GET request with token""" self._ensure_token() url = f"{self.host}{path}" merged = dict(params or {}) merged["token"] = self.api_token resp = self._session.get(url, params=merged, timeout=self.TIMEOUT, **kwargs) if not resp.ok: raise QasApiError(f"Request failed: {resp.status_code} {resp.text}") return resp.json() def _post(self, path: str, *, params: Optional[dict] = None, **kwargs) -> dict: """POST request""" self._ensure_token() url = f"{self.host}{path}" merged = dict(params or {}) merged["token"] = self.api_token resp = self._session.post(url, params=merged, timeout=self.TIMEOUT, **kwargs) if not resp.ok: raise QasApiError(f"Request failed: {resp.status_code} {resp.text}") return resp.json() ``` The same query-parameter authentication pattern is used by share-link validation and the streaming update endpoint: ```python resp = self._session.post( f"{self.host}/get_share_detail", params={"token": self.api_token}, json={"shareurl": shareurl}, timeout=timeout, ) ``` ```python resp = self._session.post( f"{self.host}/run_script_now", params={"token": self.api_token}, json=payload, stream=True, timeout=self.TIMEOUT, ) ``` ### Technical Analysis The QAS API token is added to the query string of every authenticated request. URL query strings are commonly recorded by web-server access logs, reverse proxies, monitoring systems, browser or HTTP debugging tools, and network appliances. This gives the credential a substantia ...[truncated 1698 chars]- Remediation
View remediation
