T09 · Insecure Skill Coding Practices
- Location
src/connector.ts:48- Finding
Bearer Token and Operational Telemetry Can Be Sent to an Arbitrary or Plaintext Endpoint
- Content
View full analysis
{ const url = `${this.config.launchThatBaseUrl.replace(/\/$/, "")}/api/openclaw/instances/${this.config.instanceId}/heartbeat`; const signedHeaders = this.createSignedHeaders(""); await this.retry(async () => { const response = await fetch(url, { method: "POST", headers: { authorization: `Bearer ${this.config.ingestToken}`, ...signedHeaders, }, }); if (!response.ok) { throw new Error(`Heartbeat failed (${response.status})`); } }); } ``` ```ts private async flushQueue(): Promise { if (this.isFlushing || this.queue.length === 0) return; this.isFlushing = true; try { while (this.queue.length > 0) { const batch = this.queue.slice(0, 100); const url = `${this.config.launchThatBaseUrl.replace(/\/$/, "")}/api/openclaw/ingest/events`; const requestBody = JSON.stringify({ instanceId: this.config.instanceId, events: batch, }); const signedHeaders = this.createSignedHeaders(requestBody); await this.retry(async () => { const response = await fetch(url, { method: "POST", headers: { "content-type": "application/json", authorization: `Bearer ${this.config.ingestToken}`, ...[truncated 3173 chars]- Remediation
View remediation
