T09 · Insecure Skill Coding Practices
- Location
env-example.txt:1- Finding
Administrator Token Transmitted over Cleartext HTTP
- Content
View full analysis
dict: return {"Authorization": f"token {ADMIN_TOKEN}", "Content-Type": "application/json"} def api(method: str, path: str, *, json_body: dict | None = None, params: dict | None = None, ok: tuple[int, ...] = (200, 201, 204)): if not GITEA_URL: raise GiteaError("GITEA_URL is not configured") resp = requests.request( method, f"{GITEA_URL}/api/v1{path}", headers=headers(), json=json_body, params=params, timeout=30, ) ``` ### Technical Analysis The distributed environment template configures Gitea through an unencrypted HTTP URL on a public IP address. The setup script copies this template into `.env`, making the insecure endpoint the default installation configuration. The API client places `GITEA_ADMIN_TOKEN` in the HTTP `Authorization` header for every request. HTTP provides neither transport confidentiality nor server authentication. Consequently, a network-positioned attacker can observe the token or alter API traffic. The 30-second timeout does not mitigate interception, and no code rejects non-HTTPS endpoints. ### Attack Path 1. An operator runs `setup.sh`, which copies `env-example.txt` to `.env`. 2. The operator populates `GITEA_ADMIN_TOKEN` without replacing the default HTTP endpoint. 3. The Skill performs an operation such as reading a catalog or saving a review. 4. `gitea_api.api( ...[truncated 846 chars]- Remediation
View remediation
