T09 · Insecure Skill Coding Practices
- Location
bin/run.mjs:19- Finding
API Authentication Token Transmitted in the URL Query String
- Content
View full analysis
parameter.name === "token"); if (!tokenParam || params.token !== undefined) { return; } if (!cliToken) { fail("--token is required for this operation.", { operationId: operation.operationId, }); } params.token = cliToken; } ``` ```js function applyQueryParams(operation, params, url) { for (const parameter of operation.parameters.filter((item) => item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.searchParams, parameter.name, value); } } ``` The resulting URL, including the token, is sent to the fixed JustOneAPI HTTPS endpoint: ```js let response; try { response = await fetch(url, requestInit); } catch (error) { fail("Network request failed.", { cause: error instanceof Error ? error.message : String(error), ...[truncated 2600 chars]- Remediation
View remediation
