T09 · Insecure Skill Coding Practices
- Location
scripts/common/auth.py:50- Finding
OAuth Credentials Can Be Transmitted to an Arbitrary or Insecure Token Endpoint
- Content
View full analysis
dict[str, Any]: """Read OAuth2 config from environment variables.""" result = oauth_cfg.copy() if oauth_cfg else {} result["client_id"] = os.environ.get("EMAIL_OAUTH2_CLIENT_ID", oauth_cfg.get("client_id", "") if oauth_cfg else "") result["client_secret"] = os.environ.get("EMAIL_OAUTH2_CLIENT_SECRET", oauth_cfg.get("client_secret", "") if oauth_cfg else "") result["refresh_token"] = os.environ.get("EMAIL_OAUTH2_REFRESH_TOKEN", oauth_cfg.get("refresh_token", "") if oauth_cfg else "") result["token_url"] = os.environ.get("EMAIL_OAUTH2_TOKEN_URL", oauth_cfg.get("token_url", "") if oauth_cfg else "") r ...[truncated 2322 chars]- Remediation
View remediation
