T09 · Insecure Skill Coding Practices
- Location
bin/run.mjs:224- Finding
API Authentication Token Transmitted in the URL Query String
- Content
View full analysis
Vulnerability Details
File Location:
bin/run.mjs:73-75andbin/run.mjs:224-231
Vulnerability Type: Credential exposure through URL query parameters
Risk Level: MediumVulnerable Code
js injectToken(operation, params, args.token); validateRequired(operation, params); const baseUrl = manifest.baseUrl; const url = new URL(operation.path, ensureBaseUrl(baseUrl)); applyPathParams(operation, params, url); applyQueryParams(operation, params, url);js function appendValue(searchParams, name, value) { if (Array.isArray(value)) { for (const item of value) { appendValue(searchParams, name, item); } return; } if (value && typeof value === "object") { searchParams.append(name, JSON.stringify(value)); return; } searchParams.append(name, String(value)); }The operation manifest defines the authentication token as a required query parameter:
js { "description": "Authentication token required to access the API.", "enumValues": [], "location": "query", "name": "token", "required": true, "schemaType": "string" }Technical Analysis
The helper injects the supplied authentication token into the general parameter object. Because the manifest marks
tokenas a query parameter,applyQueryParamsultimately appends it to the request URL.HTTPS protects the URL against passive observation while it is in transit, and the code restricts requests to the declared
https://api.justoneapi.comdestination. Nevertheless, query strings are commonly recorded by API gateways, reverse proxies, server access logs, monitoring products, error reports, and diagnostic tooling. Placing reusable credentials in a URL therefore creates broader and longer-lived exposure than transmitting them in an authorization header.Sending an authentication credential to JustOneAPI is necessary for the declared functionality ...[truncated 1109 chars]
- Remediation
View remediation
Remediation Suggestions
- Prefer an HTTP authorization header rather than a query parameter:
js requestInit.headers.authorization = `Bearer ${token}`; - Remove
tokenfrom the URL parameter manifest and keep it separate from ordinary endpoint parameters. - If JustOneAPI only supports query-based authentication, coordinate an API change to support header-based credentials.
- Until header authentication is available, configure clients, gateways, reverse proxies, monitoring systems, and server logs to redact the
tokenquery parameter. - Use narrowly scoped, short-lived, and readily revocable tokens to limit the consequences of disclosure.
- Ensure exception handling and diagnostics never emit the complete request URL.
- Prefer an HTTP authorization header rather than a query parameter:
