T09 · Insecure Skill Coding Practices
- Location
scripts/rebrickable_cli.py:42- Finding
Credentials Can Be Transmitted to an Arbitrary Network Destination
- Content
View full analysis
dict[str, str]: headers = {"Accept": "application/json", "Authorization": f"key {self.api_key}"} if content_type: headers["Content-Type"] = content_type return headers def _url(self, path: str, params: dict[str, Any] | None = None) -> str: query = urllib.parse.urlencode(clean_params(params or {}), doseq=True) suffix = f"?{query}" if query else "" return f"{self.base_url}{path}{suffix}" def _request(self, method: str, url: str, body: bytes | None = None, headers: dict[str, str] | None = None) -> Any: request = urllib.request.Request(url, data=body, headers=headers or {}, method=method) try: with urllib.request.urlopen(request, timeout=self.timeout) as response: raw = response.read().decode("utf-8") ``` ```python def add_common(parser: argparse.ArgumentParser) -> None: parser.add_argument("--base-url", default=os.getenv("REBRICKABLE_BASE_URL", DEFAULT_BASE_URL), help="Rebrickable API base URL") parser.add_argument("--timeout", type=int, default=READ_TIMEOUT_SECONDS, help="HTTP timeout in seconds") ``` ```python def user_path(args: argparse.Namespace, suffix: str) -> str: token = "[from REBRICKABLE_USER_TOKEN]" if getattr(args, "dry_run", False) else quote(user_token(args)) return f"/users/{token}/{suffix.lstrip('/')}" ``` ### Technical Analysis The CLI accepts the ...[truncated 2275 chars]- Remediation
View remediation
