T09 · Insecure Skill Coding Practices
- Location
SKILL.md:45- Finding
OAuth Bearer Token Transmitted over Plaintext HTTP
- Content
View full analysis
list: token = self.auth.get_token() headers = { "Authorization": f"Bearer {token}", "distributorId": self.auth.distributor_id, "timestamp": str(int(time.time() * 1000)), "traceId": str(uuid.uuid4()), } resp = requests.get(f"{self.biz_domain}/hotels", headers=headers, timeout=10) ``` ### Technical Analysis The default test configuration sends an OAuth bearer token in the `Authorization` header to an `http://` URL. Plain HTTP provides neither transport confidentiality nor server authentication. Although the preceding OAuth exchange uses HTTPS, that protection is negated when the resulting reusable token is subsequently transmitted over an unencrypted connection. This network request is necessary for the declared hotel-query functionality, but sending authentication material over HTTP exceeds acceptable minimum-risk behavior. The client also accepts an arbitrary `biz_domain` without validating its scheme or expected hostname, making accidental token disclosure to an insecure or unintended endpoint possible. ### Attack Path 1. A user supplies a Huazhu client ID and ...[truncated 1078 chars]- Remediation
View remediation
