T09 · Insecure Skill Coding Practices
- Location
scripts/yufluent_api.py:20- Finding
Bearer Token and Business Data Can Be Transmitted over Unencrypted HTTP
- Content
View full analysis
str: base = (base_url or "").strip().rstrip("/") if not base: base = "http://localhost:8080/v1" if base.endswith("/v1"): return base return f"{base}/v1" ``` ```python def _auth_headers(api_key: str) -> dict[str, str]: return { "Authorization": f"Bearer {api_key}", "Accept": "application/json", } ``` ```python def _post_json( url: str, *, api_key: str, body: dict[str, Any] | None = None, timeout: float, ) -> requests.Response: kwargs: dict[str, Any] = { "headers": _json_headers(api_key) if body is not None else _auth_headers(api_key), "timeout": timeout, } if body is not None: kwargs["json"] = body return requests.post(url, **kwargs) ``` ```python def run_skill( skill_id: str, payload: dict[str, Any], *, api_key: str | None = None, base_url: str | None = None, timeout: float = 120.0, ) -> dict[str, Any]: key = (api_key or os.getenv("TOKENAPI_KEY", "")).strip() if not key: msg = ( "未配置 TOKENAPI_KEY。\n" "新用户请前往 https://claw.changzhiai.com/login 注册,即送体验积分。\n" "获取密钥后设置环境变量:export TOKENAPI_KEY=tk-..." ) raise YufluentApiError(msg) root = base_url or os.getenv("TOKENAPI_BASE_URL", "") url = skill_run_url(root, skill_id) try: resp = _post_json(url, api_key=key, body=payload, timeout=timeout) ``` ### Technical Analysis The API base URL is accepted without validating its scheme or destination. Although the default `http://localhost:8080/v1` endpoint can be appropriate for a local proxy ...[truncated 1955 chars]- Remediation
View remediation
str: parsed = urlsplit(url) if parsed.username or parsed.password: raise ValueError("Embedded URL credentials are not allowed") hostname = parsed.hostname if not hostname: raise ValueError("API URL must include a hostname") is_loopback = hostname == "localhost" try: is_loopback = is_loopback or ipaddress.ip_address(hostname).is_loopback except ValueError: pass if parsed.scheme != "https" and not ( parsed.scheme == "http" and is_loopback ): raise ValueError("HTTPS is required for non-loopback API endpoints") return url ``` ]]>
