T09 · Insecure Skill Coding Practices
- Location
vipshop-product-detail/scripts/exchange_link_builder.py:40- Finding
Reusable access token exposed through generated product URLs
- Content
View full analysis
str: return "5fb86e55b72bfc50f083049130e5e76a75c2cbda6bbd6e51d59668057f5c1715" ``` ```python token_file = Path.home() / ".vipshop-user-login" / "tokens.json" with open(token_file, 'r', encoding='utf-8') as f: data = json.load(f) cookies = data.get('cookies', {}) token = cookies.get("PASSPORT_ACCESS_TOKEN", "") ``` ```python timestamp = int(time.time() * 1000) data_obj = {"t": token, "ts": timestamp} json_str = json.dumps(data_obj, separators=(",", ":")) base64_str = base64.b64encode( json_str.encode("utf-8") ).decode("utf-8") signature = _generate_signature(base64_str, secret) base_url = "https://passport.vip.com/exchangeTokenFromApp" full_url = ( f"{base_url}?" f"dt={urllib.parse.quote(base64_str)}&" f"sg={signature}&" f"src={urllib.parse.quote(target_url)}" ) return full_url ``` ### Technical Analysis The `PASSPORT_ACCESS_TOKEN` is read from the locally protected login-state file and inserted into a JSON object under the `t` property. That object is only Base64-encoded before being placed in the `dt` query parameter. Base64 is a reversible transport encoding and provides no confidentiality. Anyone who receives a generated product URL can URL-decode and Base64-decode `dt` to recover the underlying access token. The HMAC signature does not protect token confidentiality. Moreover, the signing secret is hardcoded in every copy of the builder, so possession ...[truncated 1930 chars]- Remediation
View remediation
