T09 · Insecure Skill Coding Practices
- Location
scripts/_temu_token_store.py:10- Finding
Temu access tokens are stored in plaintext without restrictive file permissions
- Content
View full analysis
str: return os.environ.get("TEMU_TOKEN_STORE_PATH", DEFAULT_STORE_PATH) ``` ```python def _save_store(data: dict) -> None: path = store_path() parent = os.path.dirname(path) if parent: os.makedirs(parent, exist_ok=True) with open(path, "w", encoding="utf-8") as f: json.dump(data, f, indent=2, ensure_ascii=False) f.write("\n") ``` ```python def save_token( store_key: str, site: str, management_type: str, access_token: str, token_purpose: str = "default", label: str | None = None, ) -> dict: data = _load_store() store = _find_store(data, store_key) if store is None: store = {"storeKey": store_key, "label": label or store_key, "tokens": []} data["stores"].append(store) elif label: store["label"] = label key = _token_key(site, management_type, token_purpose) entry = { "site": site, "managementType": management_type, "tokenPurpose": token_purpose, "accessToken": access_token, "updatedAt": _utc_now(), } ``` ### Technical Analysis Temu access tokens are serialized directly into a plaintext JSON file. The code uses ordinary `os.makedirs()` and `open(..., "w")` calls without explicitly enforcing owner-only permissions. Consequently, the effective directory and file permissions depend on the process umask and the state of any existing path. On a shared system, a permissive umask can make the credential store readable by other local users. The implementation also does not guard against symbolic-link replacement, does not use atomic replacement, and does not encrypt the stor ...[truncated 1201 chars]- Remediation
View remediation
