T09 · Insecure Skill Coding Practices
- Location
scripts/translate.py:44- Finding
Bearer API Key May Be Forwarded Across Trust Boundaries During Redirects
- Content
View full analysis
Vulnerability Details
File Location:
scripts/translate.py:44-51, with authenticated requests originating atscripts/translate.py:92-98,106-121,172-180,202-203,249-256, and270-276
Vulnerability Type: Cross-origin credential disclosure through automatic redirects
Risk Level: HighVulnerable Code
python def api_request(method, url, headers=None, data=None, json_data=None): """Make HTTP request using only stdlib.""" if headers is None: headers = {} if json_data is not None: data = json.dumps(json_data).encode("utf-8") headers.setdefault("Content-Type", "application/json") req = urllib.request.Request(url, data=data, headers=headers, method=method) try: with urllib.request.urlopen(req, timeout=300) as resp: body = resp.read().decode("utf-8") return json.loads(body) if body else {}Authenticated callers provide the credential through an ordinary request header:
python headers = {"Authorization": f"Bearer {api_key}"} result = api_request( "POST", f"{API_BASE}/translate", headers=headers, json_data=payload )The direct document-upload path similarly enables default redirect handling:
python headers = { "Authorization": f"Bearer {api_key}", "Content-Type": content_type, } req = urllib.request.Request(create_url, data=body, headers=headers, method="POST") try: with urllib.request.urlopen(req, timeout=120) as resp: upload_result = json.loads(resp.read().decode("utf-8"))Technical Analysis
urllib.request.urlopen()uses Python's default redirect handler. The implementation does not disable redirects, validate the redirect destination, restrict redirects to the original HTTPS origin, or explicitly remove theAuthorizationheader when the origin changes.Consequently, an authenticated request that receives a ...[truncated 1658 chars]
- Remediation
View remediation
Remediation Suggestions
- Disable automatic redirects for every request carrying an authorization credential.
- If redirects are operationally required, implement a custom redirect handler that:
- Allows only
httpsdestinations. - Allows only an explicit set of trusted 360 API hosts.
- Rejects redirects that change scheme, hostname, or port.
- Removes
Authorizationwhenever the origin changes. - Enforces a small maximum redirect count.
- Allows only
- Keep the API key in an unredirected or otherwise origin-bound header where supported by the HTTP client.
- Centralize all authenticated requests in one hardened request function; the direct document-upload requests should not bypass it.
- Use a dedicated API key with minimum billing scope, quotas, and usage alerts.
- Rotate the API key if execution logs or network telemetry indicate an unexpected redirect.
- Add tests asserting that cross-origin redirects are rejected and that credentials are never sent to a redirected host.
