T09 · Insecure Skill Coding Practices
- Location
scripts/exchange_link_builder.py:145- Finding
Vipshop Access Token Exposed in Generated Output URL
- Content
View full analysis
str: """ 获取 secret key Returns: secret key 字符串 """ return "5fb86e55b72bfc50f083049130e5e76a75c2cbda6bbd6e51d59668057f5c1715" ``` ```python def _get_token() -> str: """ 从 token 文件获取 PASSPORT_ACCESS_TOKEN 参考 search.py 的 load_login_tokens 方法 Returns: token 字符串,如果未获取到则返回空字符串 """ log("=" * 50) log("开始获取 token...") token_file = Path.home() / ".vipshop-user-login" / "tokens.json" log(f"token 文件路径: {token_file}") if not token_file.exists(): log(f"❌ token 文件不存在: {token_file}") return "" log("✅ token 文件存在") try: with open(token_file, 'r', encoding='utf-8') as f: data = json.load(f) log(f"✅ 成功读取 token 文件") log(f" 数据类型: {type(data)}") if data and isinstance(data, dict) and 'cookies' in data: log("✅ 数据格式正确,包含 cookies 字段") expires_at = data.get('expires_at') log(f" expires_at: {expires_at}") if expires_at and time.time() > expires_at: log("❌ token 已过期") return "" cookies = data.get('cookies', {}) log(f" cookies 数量: {len(cookies)}") log(f" cookies 键: {list(cookies.keys())}") token = cookies.get("PASSPORT_ACCESS_TOKEN", "") if token: log(f"✅ 成功获取 PASSPORT_ACCESS_TOKEN") log(f" token 长度: {len(token)}") log(f" token 前10位: {token[:10]}...") return token else: log("❌ cookies 中不存在 PASSPORT_ACCESS_TOKEN") return "" else: ...[truncated 5196 chars]- Remediation
View remediation
