T09 · Insecure Skill Coding Practices
- Location
scripts/_temu_token_store.py:10- Finding
Temu Access Tokens Are Stored in Plaintext Without Restrictive Filesystem Permissions
- Content
View full analysis
str: return os.environ.get("TEMU_TOKEN_STORE_PATH", DEFAULT_STORE_PATH) def _save_store(data: dict) -> None: path = store_path() parent = os.path.dirname(path) if parent: os.makedirs(parent, exist_ok=True) with open(path, "w", encoding="utf-8") as f: json.dump(data, f, indent=2, ensure_ascii=False) f.write("\n") def save_token( store_key: str, site: str, management_type: str, access_token: str, token_purpose: str = "default", label: str | None = None, ) -> dict: data = _load_store() store = _find_store(data, store_key) if store is None: store = {"storeKey": store_key, "label": label or store_key, "tokens": []} data["stores"].append(store) elif label: store["label"] = label key = _token_key(site, management_type, token_purpose) entry = { "site": site, "managementType": management_type, "tokenPurpose": token_purpose, "accessToken": access_token, "updatedAt": _utc_now(), } ... _save_store(data) ``` ### Technical Analysis The token store writes Temu access tokens directly into a plaintext JSON file. Neither the parent directory nor the file is explicitly created with owner-only permissions. Their effective permissions therefore depend on the current process umask and any pre-existing filesystem object. The implementation also uses a normal `open(path, "w")` operation without checking whether the destination is a regular file owned by the current user. It does not reject symbolic links, use exclusive creation, or perform an atomic temporary-file replacement. A ...[truncated 1397 chars]- Remediation
View remediation
