T09 · Insecure Skill Coding Practices
- Location
scripts/crawl.py:598- Finding
Stored credentials can be submitted to an unvalidated attacker-controlled URL
- Content
View full analysis
str: return (url or "").strip().rstrip("/") def derive_login_url(base_url: str) -> str: cleaned = normalize_url(base_url) if not cleaned: return "" return f"{cleaned}{DEFAULT_LOGIN_PATH}" ``` ```python def normalize_school_fields( previous: dict[str, Any] | None = None, *, base_url: str | None = None, login_url: str | None = None ) -> dict[str, Any]: school = dict(previous or {}) if base_url is not None: school["base_url"] = normalize_url(base_url) if login_url is not None: school["login_url"] = normalize_url(login_url) resolved_base_url = normalize_url(school.get("base_url")) resolved_login_url = normalize_url(school.get("login_url")) or derive_login_url(resolved_base_url) if not resolved_base_url: print_json( { "ok": False, "error_code": "MISSING_REQUIRED_FIELDS", "message": "学校 URL 为空,无法保存", "required": ["school", "base_url"], }, exit_code=2, ) school["base_url"] = resolved_base_url school["login_url"] = resolved_login_url return school ``` ```python def cmd_school_add(args: argparse.Namespace) -> None: path = Path(args.config) config = load_config(path) schools = ensure_schools(config) school_name = require_school_name(args.school, action="school-add") previous = schools.get(school_name) if previous and not args.force: print_json( { "ok": False, "error_code": "SCHOOL_ALREADY_EXISTS", "message": f"学校 {school_name} 已存在", "school": school_name ...[truncated 2341 chars]- Remediation
View remediation
