T09 · Insecure Skill Coding Practices
- Location
bin/run.mjs:25- Finding
API Authentication Token Exposed in URL Query String
- Content
View full analysis
item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.searchParams, parameter.name, value); } } ``` The same query-string authentication requirement is declared in `generated/operations.json:15-22` and `generated/operations.md:18`. ### Technical Analysis The authentication token is defined as a query parameter. After `injectToken` places the supplied credential in `params.token`, `applyQueryParams` serializes it into the request URL. The resulting request has the form: ```text https://api.justoneapi.com/api/imdb/news-by-category-query/v1?token=&category=TOP ``` Sending an authentication credential to the declared JustOneAPI endpoint is necessary for the Skill's functionality. However, placing the credential in the URL creates unnecessary exposure. Complete URLs are commonly retained by API gateways, reverse proxies, access logs, observability systems, debugging tools, and server-side request telemetry. HTTPS protects the URL while it is in transit but does not prevent authorized intermediaries or endpoint infrastructure from rec ...[truncated 1526 chars]- Remediation
View remediation
