T09 · Insecure Skill Coding Practices
- Location
src/api/search.js:59- Finding
API Token Transmitted in URL Query Parameters
- Content
View full analysis
Vulnerability Details
File Location:
src/api/search.js:59-78
Additional Affected Locations:src/api/comment.js:38-52,src/api/comment.js:67-79,src/api/post.js:23-36,src/api/post.js:50-61,src/api/hot.js:19-22,src/utils/request.js:91-105,src/utils/request.js:126-136
Vulnerability Type: Sensitive credential exposure through URL query strings
Risk Level: MediumVulnerable Code
javascript const params = { _: Date.now(), token: token, }; const data = { keyword, sort_type: sort, publish_time: time, filter_duration: duration, content_type: content, limit: limit, }; return await requestApi( "POST", "/api/douyin/general-search/keyword", params, data, constants.CREATE_MAX_ATTEMPTS, "创建任务", );The shared request utility converts these parameters, including the token, into the URL:
javascript params.skill_name = skillName(); const fullPath = `${path}?${querystring.stringify(params)}`; const jsonData = JSON.stringify(data); const options = { host: constants.BASE_URL, path: fullPath, method: "POST", headers: { "Content-Type": "application/json", "Accept-Encoding": "identity", "Content-Length": Buffer.byteLength(jsonData), }, };Technical Analysis
The
GUAIKEI_API_TOKENcredential is copied intoparamsand serialized into the request URL. This pattern is used by search, post, comment, and hot-list API operations.HTTPS protects the URL while it is in transit, but it does not prevent the URL from being recorded at endpoints or within operational infrastructure. Query strings are commonly captured by:
- Reverse-proxy and web-server access logs
- API gateways, load balancers, and monitoring systems
- Error reports and distributed tracing systems
- Server-side analytics and request histories
- Debugging tools that record complete request paths
Unlike a ...[truncated 1876 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove
tokenfrom every query-parameter object. - Send the credential in an HTTP authorization header, preferably:
javascript headers: { Authorization: `Bearer ${token}`, "Content-Type": "application/json", "Accept-Encoding": "identity" } - Refactor
request(),postJson(), andgetJson()to accept the token separately from ordinary request parameters. - Ensure retry and error messages never include request headers or complete request URLs.
- Configure server, proxy, API-gateway, tracing, and monitoring systems to redact
Authorization,token, and equivalent credential fields. - Rotate existing API tokens because historical server or monitoring logs may already contain them.
- Use short-lived, scoped tokens where the service supports them, and enforce revocation and quota-alerting controls.
- Add an automated test asserting that generated request paths never contain
token,api_key, or other credential parameters.
- Remove
