T09 · Insecure Skill Coding Practices
- Location
scripts/bitrix24_client.py:969- Finding
Credentials and business data can be transmitted to arbitrary or plaintext endpoints
- Content
View full analysis
str: domain = self.tenant.domain.strip().rstrip("/") if not domain.startswith("http://") and not domain.startswith("https://"): domain = f"https://{domain}" if self.tenant.auth_mode == "webhook": if not self.tenant.webhook_user_id or not self.tenant.webhook_code: raise ValueError("webhook_user_id and webhook_code are required for webhook mode") return ( f"{domain}/rest/" f"{self.tenant.webhook_user_id}/{self.tenant.webhook_code}/{method}" ) if rest_v3: return f"{domain}/rest/api/{method}" return f"{domain}/rest/{method}" def _post_json(self, url: str, payload: Dict[str, Any]) -> Dict[str, Any]: req = urllib.request.Request( url=url, method="POST", headers={ "Content-Type": "application/json", "Accept": "application/json", }, data=json.dumps(payload).encode("utf-8"), ) with urllib.request.urlopen(req, timeout=self.timeout) as resp: raw = resp.read().decode("utf-8") parsed = self._safe_json_parse(raw) if parsed is None: raise BitrixAPIError("Invalid JSON response", code="INVALID_JSON") return parsed ``` The destination originates directly from the environment: ```python def load_tenant_config_from_env() -> Tuple[TenantConfig, TokenStore]: domain = os.getenv("B24_DOMAIN", "").strip() auth_mode = os.getenv("B24_AUTH_MODE", "webhook").strip().lower() if not domain: raise ValueError("B24_DOMAIN is required") if auth_mode not in {"webhook", "oauth"}: raise ValueError("B24_AUTH_MODE must be 'webhook' or 'oauth' ...[truncated 2803 chars]- Remediation
View remediation
