T09 · Insecure Skill Coding Practices
- Location
src/utils/request.js:96- Finding
API Token Exposed in URL Query Parameters
- Content
View full analysis
Vulnerability Details
File Location:
src/api/search.js:59-63,src/api/search.js:104-107,src/api/comment.js:38-41,src/api/comment.js:67-71,src/api/post.js:23-28,src/api/hot.js:19-21, andsrc/utils/request.js:96-120
Vulnerability Type: Sensitive credential exposure through URL query parameters
Risk Level: MediumVulnerable Code
The API modules place the authentication token in the request parameter object:
js const params = { _: Date.now(), token: token, };Search and comment result queries similarly include the token:
js const params = { _: Date.now(), token: token, keyword: keyword, sort_type: sort, publish_time: time, filter_duration: duration, content_type: content, limit: limit, };The shared request function serializes these parameters directly into the URL:
js params.skill_name = skillName(); const fullPath = `${path}?${querystring.stringify(params)}`; const jsonData = JSON.stringify(data); const options = { host: constants.BASE_URL, path: fullPath, method: "POST", headers: { "Content-Type": "application/json", "Accept-Encoding": "identity", "Content-Length": Buffer.byteLength(jsonData), }, }; return await request(options, jsonData);Technical Analysis
GUAIKEI_API_TOKENis an authentication secret, but the application sends it as atokenquery parameter for search, comment, post, and hot-list requests. Although the connection uses HTTPS, TLS only protects the request while it is in transit. It does not prevent the complete URL from being retained by the destination service, API gateways, reverse proxies, access logs, application-performance monitoring systems, diagnostic traces, or infrastructure telemetry.Query strings are commonly logged by default. Consequently, users and operators who can read URL logs may obtain a reusable API token even if they ...[truncated 1346 chars]
- Remediation
View remediation
Remediation Suggestions
-
Remove
tokenfrom all URL parameter objects. -
Send the secret through an authorization header, for example:
js const options = { host: constants.BASE_URL, path: fullPath, method: "POST", headers: { Authorization: `Bearer ${token}`, "Content-Type": "application/json", "Accept-Encoding": "identity", "Content-Length": Buffer.byteLength(jsonData), }, }; -
If the service does not support bearer authentication, use a dedicated secret header such as
X-API-Keyand update the server accordingly. -
Configure API gateways, reverse proxies, monitoring systems, and server logs to redact authentication headers and any legacy
tokenquery parameter. -
Avoid including secrets in error messages, tracing attributes, or request diagnostics.
-
Rotate tokens that have previously been transmitted in URLs because historical infrastructure logs may retain them.
-
Add automated tests that reject outbound request paths containing
token=.
-
