T09 · Insecure Skill Coding Practices
- Location
scripts/client.py:72- Finding
Bearer Token Can Be Transmitted to an Arbitrary or Plaintext Endpoint
- Content
View full analysis
", method="INIT", status_code=0, ) ``` ```python def _build_url(self, path: str, query: dict[str, Any] | None = None) -> str: url = f"{self.base_url}/{path.lstrip('/')}" if query: # Drop keys whose value is None filtered = {k: v for k, v in query.items() if v is not None} if filtered: url += ("&" if "?" in url else "?") + urllib.parse.urlencode(filtered, doseq=True) return url ``` ```python url = self._build_url(path, query) headers: dict[str, str] = { "Authorization": f"Bearer {self.token}", "Accept": "application/json", } if extra_headers: headers.update(extra_headers) encoded_body: bytes | None = None if body is not None: encoded_body = json.dumps(body).encode("utf-8") headers["Content-Type"] = "application/json" safe_url = self._sanitise(url, self.token) logger.debug(">>> %s %s", method, safe_url) if encoded_body: logger.debug(" body: %s", self._sanitise(encoded_body.decode()[:500], self.token)) last_exc: Exception | None = None for attempt in range(1, MAX_RETRIES + 2): t0 = time.monotonic() try: req = urllib.request.Request( url, data=encoded_body, headers=headers, method=method.upper(), ) with urllib.request.urlopen(req) as resp: ``` ### Technical Analysis The client ...[truncated 2175 chars]- Remediation
View remediation
