T09 · Insecure Skill Coding Practices
- Location
scripts/yufluent_api.py:21- Finding
Bearer Token and Review Data Can Be Transmitted over an Untrusted Plaintext Endpoint
- Content
View full analysis
str: base = (base_url or "").strip().rstrip("/") if not base: base = "http://localhost:8080/v1" if base.endswith("/v1"): return base return f"{base}/v1" ``` ```python def _auth_headers(api_key: str) -> dict[str, str]: return { "Authorization": f"Bearer {api_key}", "Accept": "application/json", } def _json_headers(api_key: str) -> dict[str, str]: return {**_auth_headers(api_key), "Content-Type": "application/json"} ``` ```python def _post_json( url: str, *, api_key: str, body: dict[str, Any] | None = None, timeout: float, ) -> requests.Response: kwargs: dict[str, Any] = { "headers": _json_headers(api_key) if body is not None else _auth_headers(api_key), "timeout": timeout, } if body is not None: kwargs["json"] = body return requests.post(url, **kwargs) ``` ```python root = base_url or os.getenv("TOKENAPI_BASE_URL", "") url = skill_run_url(root, skill_id) try: resp = _post_json(url, api_key=key, body=payload, timeout=timeout) ``` ### Technical Analysis The client obtains its API endpoint from the `TOKENAPI_BASE_URL` environment variable and accepts the value without validating its scheme or destination. The URL can therefore identify an arbitrary HTTP or HTTPS server. Every request includes the `TOKENAPI_KEY` bearer credential in the `Authorization` header. Skill requests also contain the complete review payload, including any product information or personal data inadvertently present in the supplied reviews. The default `http://localhost:8080/v1 ...[truncated 2031 chars]- Remediation
View remediation
