T09 · Insecure Skill Coding Practices
- Location
bin/run.mjs:248- Finding
API Token Exposed Through Process Arguments and URL Query Parameters
- Content
View full analysis
"}' ``` The token is defined as a query parameter at `bin/run.mjs:19-29`: ```javascript { "defaultValue": null, "description": "User's authentication token.", "enumValues": [], "location": "query", "name": "token", "required": true, "schemaType": "string" }, ``` It is accepted as a command-line argument at `bin/run.mjs:173-176`: ```javascript if (flag === "--token") { parsed.token = value; index += 1; continue; } ``` The credential is inserted into the request parameters at `bin/run.mjs:205-214`: ```javascript function injectToken(operation, params, cliToken) { const tokenParam = operation.parameters.find((parameter) => parameter.name === "token"); if (!tokenParam || params.token !== undefined) { return; } if (!cliToken) { fail("--token is required for this operation.", { operationId: operation.operationId, }); } params.token = cliToken; } ``` Every parameter declared with a query location, including the token, is appended to the URL at `bin/run.mjs:248-256`: ```javascript function applyQueryParams(operation, params, url) { for (const parameter of operation.parameters.filter((item) => item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.searchParams, parameter.name, value); } } ``` The resulting URL is sent to the fixed JustOneAPI endpoint at `bin/run.mjs:99-118`: ```javascript const baseUrl = manifest.baseUrl; const url = new URL(operation.path, ensureBaseUr ...[truncated 3482 chars]- Remediation
View remediation
