T09 · Insecure Skill Coding Practices
- Location
src/utils/request.js:94- Finding
API Token Exposed in URL Query Strings
- Content
View full analysis
Vulnerability Details
File Location:
src/utils/request.js:94-98, 119-123; token-bearing parameters originate insrc/api/search.js:59-77, 104-118,src/api/comment.js:38-52, 67-78,src/api/post.js:23-35, 50-60, andsrc/api/hot.js:19-22
Vulnerability Type: Credential exposure through URL query parameters
Risk Level: MediumVulnerable Code
Token-bearing request construction in
src/api/search.js:js const params = { _: Date.now(), token: token, }; const data = { keyword, sort_type: sort, publish_time: time, filter_duration: duration, content_type: content, limit: limit, }; return await requestApi( "POST", "/api/douyin/general-search/keyword", params, data, constants.CREATE_MAX_ATTEMPTS, "创建任务", );Query-string construction in
src/utils/request.js:js params.skill_name = skillName(); const fullPath = `${path}?${querystring.stringify(params)}`; const jsonData = JSON.stringify(data); const options = { host: constants.BASE_URL, path: fullPath, method: "POST", headers: { "Content-Type": "application/json", "Accept-Encoding": "identity", "Content-Length": Buffer.byteLength(jsonData), }, }; return await request(options, jsonData);The GET helper uses the same pattern:
js params._ = Date.now(); const fullPath = `${path}?${querystring.stringify(params)}`; const options = { host: constants.BASE_URL, path: fullPath, method: "GET", headers: { "Accept-Encoding": "identity" }, }; return await request(options);Technical Analysis
Every API operation adds
GUAIKEI_API_TOKENto the request parameter object. Both the POST and GET transport helpers serialize that object into the URL query string.HTTPS protects the full request target while it is transmitted over the network, but it does not prevent the URL from being recorded after TLS t ...[truncated 1700 chars]
- Remediation
View remediation
Remediation Suggestions
-
Remove
tokenfrom every query parameter object in the API modules. -
Pass the credential separately to the transport layer and place it in a dedicated header, preferably:
js headers: { Authorization: `Bearer ${token}`, "Content-Type": "application/json", "Accept-Encoding": "identity", } -
If the server does not support bearer authentication, use a dedicated secret header such as
X-API-Tokenand update the server accordingly. -
Ensure HTTP access logs, traces, exception reports, and proxy diagnostics redact authorization headers and any legacy
tokenquery parameter. -
Reject redirects to untrusted destinations if redirect support is added later, so authorization headers cannot be forwarded across origins.
-
Rotate tokens that may already have been transmitted through query strings.
-
Revise the documentation to distinguish local logging behavior from server-side or intermediary logging.
-
Add automated tests asserting that generated request paths never contain
token=or the configured credential.
-
