T09 · Insecure Skill Coding Practices
- Location
push-to-cloud.js:67- Finding
Configurable HTTP endpoint can receive publishing credentials and user content
- Content
View full analysis
{ const u = new URL(apiBase); const lib = u.protocol === 'http:' ? http : https; const data = Buffer.from(JSON.stringify(body), 'utf8'); const req = lib.request( { hostname: u.hostname, port: u.port || (u.protocol === 'http:' ? 80 : 443), ``` `push-to-cloud.js:141-145`: ```javascript const openId = String(cfg.openId || '').trim(); if (!openId) throw new Error('config.json is missing openId'); const skillKey = String(cfg.skillKey || '').trim(); if (!skillKey) throw new Error('config.json is missing skillKey'); const apiBase = String(cfg.apiBase || DEFAULT_API).trim() || DEFAULT_API; ``` `push-to-cloud.js:176-188`: ```javascript body = { action: 'sendToCloud', openId, skillKey, serverInstanceIds, categoryId, title: titleFromHtml(content), content, publishMode, ...(coverHtml ? { coverHtml } : {}), }; ``` `push-to-wechat-mp.js:119-135`: ```javascript function postJson(urlStr, body, timeoutMs = 120000) { const payload = JSON.stringify(body); const u = new URL(urlStr); const lib = u.protocol === 'https:' ? https : http; const port = u.port || (u.protocol === 'https:' ? 443 : 80); return new Promise((resolve, reject) => { const req = lib.request( { hostname: u.hostname, port, path: u.pathname + u.search, method: 'POST', headers: { 'Content-Type': 'application/json; charset=utf-8', 'Content-Length': Buffer.byteLength(payload, 'utf8'), ``` `push-to-wechat-mp.js:295-303`: ```javascript const body = { action: 'sendToWechat', openId: cfg ...[truncated 2080 chars]- Remediation
View remediation
