T09 · Insecure Skill Coding Practices
- Location
scripts/herdsman_client.py:238- Finding
Bearer Credential Disclosure Through Unrestricted Cross-Origin Media Downloads
- Content
View full analysis
str: request = Request(url, headers=self._headers()) actual_timeout = timeout if timeout is not None else self.timeout try: with urlopen(request, timeout=actual_timeout) as response: data = response.read() except HTTPError as exc: raw = exc.read().decode("utf-8", errors="replace") raise HerdsmanAPIError(raw or f"http error {exc.code}", status_code=exc.code, body=raw) from exc except URLError as exc: raise HerdsmanAPIError(f"download failed: {exc}") from exc return write_bytes(output_path, data) ``` The authorization header used by this function is constructed as follows: ```python def _headers(self, extra_headers: Optional[Dict[str, str]] = None) -> Dict[str, str]: headers: Dict[str, str] = {} if self.api_key: headers["Authorization"] = "Bearer " + self.api_key if extra_headers: headers.update(extra_headers) return headers ``` A representative caller trusts a URL contained in the model-service response: ```python url = item.get("url", "") if not url: print(f"Image {index + 1} returned empty") continue if target_path and (args.download or args.auto_save): try: saved = client.download_to_file(url, target_path, timeout=120) print(f"Image {index + 1} downloaded: {saved}") except HerdsmanAPIError as exc: print(json.dumps(exc.to_dict(), indent=2, ensure_ascii=False), file=sys.stderr) ...[truncated 2853 chars]- Remediation
View remediation
