T09 · Insecure Skill Coding Practices
- Location
bin/run.mjs:195- Finding
API Token Transmitted in the URL Query String
- Content
View full analysis
parameter.name === "token"); if (!tokenParam || params.token !== undefined) { return; } if (!cliToken) { fail("--token is required for this operation.", { operationId: operation.operationId, }); } params.token = cliToken; } ``` ```js // bin/run.mjs:195-202 function applyQueryParams(operation, params, url) { for (const parameter of operation.parameters.filter((item) => item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.searchParams, parameter.name, value); } } ``` The resulting URL is passed directly to the network request: ```js response = await fetch(url, requestInit); ``` ### Technical Analysis The operation manifest declares the access token as a required query parameter. `injectToken()` copies the credential supplied through `--token` into `params.token`, after which `applyQueryParams()` appends it to the request URL. Consequently, requests have the following effective form: ```text https://api.justoneapi.com/api/jd/get-item-detail/v1?token=&itemId= ``` HTTPS encrypts the URL while it is in transit, but it does not prevent the complete URL from being retained by components that process requests. Query strings are commonly recorded by API gateways, reverse proxies, server access logs, observability systems, di ...[truncated 2266 chars]- Remediation
View remediation
