T09 · Insecure Skill Coding Practices
- Location
bin/run.mjs:22- Finding
API Credential Exposed in URL Query String
- Content
View full analysis
parameter.name === "token"); if (!tokenParam || params.token !== undefined) { return; } if (!cliToken) { fail("--token is required for this operation.", { operationId: operation.operationId, }); } params.token = cliToken; } ``` ```js function applyQueryParams(operation, params, url) { for (const parameter of operation.parameters.filter((item) => item.location === "query")) { const value = params[parameter.name]; if (value === undefined) { continue; } appendValue(url.searchParams, parameter.name, value); } } ``` ### Technical Analysis The operation metadata defines the API token as a query parameter. `injectToken()` copies the supplied credential into `params.token`, after which `applyQueryParams()` places it in the request URL as `?token=`. HTTPS protects the URL against passive observation while it is transmitted, and the destination is the fixed, documented host `api.justoneapi.com`. Therefore, the audit found no evidence that the token is deliberately sent to an unrelated party. Nevertheless, placing authentication credentials in a URL is an insecure coding practice because complete URLs are frequently retained by reverse proxies, API gateways, access logs, tracing platforms, monitoring ag ...[truncated 1637 chars]- Remediation
View remediation
