T09 · Insecure Skill Coding Practices
- Location
scripts/setup_smartthings.py:17- Finding
OAuth Authorization Code Disclosed to Third-Party Redirect Service
- Content
View full analysis
dict: return { "appName": app_name, "displayName": DEFAULT_DISPLAY_NAME, "description": DEFAULT_DESCRIPTION, "appType": "API_ONLY", "oauth": { "clientName": DEFAULT_DISPLAY_NAME, "scope": DEFAULT_SCOPES, "redirectUris": [DEFAULT_REDIRECT_URI], }, } ``` ```python parser.add_argument( "--redirect-uri", default=DEFAULT_REDIRECT_URI, help=f"Redirect URI for OAuth (default: {DEFAULT_REDIRECT_URI}).", ) ``` ```python if not args.auth_code: auth_url = build_authorize_url(auth_base, client_id, redirect_uri, scopes) print("Open this URL on your phone and complete SmartThings login:") print(auth_url) ``` The associated documentation states: ```text Redirect URI defaults to https://httpbin.org/get (can be overridden via redirect-uri option). ``` ```text The default redirect uses https://httpbin.org/get to show the code in the URL; you can switch to your own redirect URI if you don’t want to use httpbin. ``` ### Technical Analysis The default OAuth application configuration registers `https://httpbin.org/get` as its redirect URI. After authentication, SmartThings redirects the browser to that unrelated service with the OAuth authorization code in the query string. Consequently, the authorization code and associated request metadata are transmitted to infrastructure outside SmartThings and outside the user's control. The third-party service can process or log the compl ...[truncated 1893 chars]- Remediation
View remediation
/callback`, using a dynamically selected local port where SmartThings permits it. 3. Alternatively, require the user to explicitly provide a redirect URI hosted on infrastructure they control. 4. Do not offer unrelated request-inspection services as recommended OAuth redirect endpoints. 5. Generate and validate a cryptographically random OAuth `state` value to protect the authorization response from request substitution and CSRF. 6. Use PKCE with an S256 code challenge where supported, so interception of the authorization code alone is insufficient to complete the exchange. 7. Update `SKILL.md` to explain the trust and confidentiality requirements for redirect endpoints. ]]>
