T09 · Insecure Skill Coding Practices
- Location
src/utils/request.js:94- Finding
API Token Exposed in URL Query Strings
- Content
View full analysis
Vulnerability Details
File Location:
src/utils/request.js:94-120,src/utils/request.js:123-140; token parameters originate insrc/api/comment.js:37-52,66-80,src/api/search.js:59-77,104-119,src/api/post.js:23-35,50-60, andsrc/api/hot.js:19-22
Vulnerability Type: Credential exposure through URL query parameters
Risk Level: MediumVulnerable Code
src/api/comment.js:37-52:js async function createCommentTask(token, url, limit) { const params = { _: Date.now(), token: token, }; const data = { url, limit, }; return await requestApi( "POST", "/api/douyin/comment/url", params, data, constants.CREATE_MAX_ATTEMPTS, "创建任务", ); }src/utils/request.js:94-120:js async function postJson(path, params, data) { if (!path || typeof path !== "string") { throw new SkillError("PATH_INVALID", "path 必须是非空字符串"); } if (!params || typeof params !== "object") { throw new SkillError("PARAM_INVALID", "params 必须是对象"); } if (!data || typeof data !== "object") { throw new SkillError("DATA_INVALID", "data 必须是对象"); } params.skill_name = skillName(); const fullPath = `${path}?${querystring.stringify(params)}`; const jsonData = JSON.stringify(data); const options = { host: constants.BASE_URL, path: fullPath, method: "POST", headers: { "Content-Type": "application/json", "Accept-Encoding": "identity", "Content-Length": Buffer.byteLength(jsonData), }, }; return await request(options, jsonData); }src/utils/request.js:123-140:js async function getJson(path, params) { if (!path || typeof path !== "string") { throw new SkillError("PATH_INVALID", "path 必须是非空字符串"); } if (!params || typeof params !== "object") { throw new SkillError("PARAM_INVALID", "params 必须是对象"); } par ...[truncated 2102 chars]- Remediation
View remediation
Remediation Suggestions
-
Remove
tokenfrom every query parameter object. -
Transmit credentials through a dedicated header, preferably:
js headers: { Authorization: `Bearer ${token}`, "Content-Type": "application/json", "Accept-Encoding": "identity", } -
Refactor
getJsonandpostJsonto accept authentication separately from ordinary request parameters so callers cannot accidentally serialize secrets into URLs. -
Configure the API service, proxies, and monitoring infrastructure to redact
Authorizationand other credential-bearing headers. -
Avoid printing request options or authentication headers in errors and debug output.
-
Rotate existing tokens because historical URL logs may already contain them.
-
Add automated tests asserting that generated request paths never contain
token,authorization, or the configured secret value.
-
