T09 · Insecure Skill Coding Practices
- Location
src/utils/request.js:89- Finding
API Credential Exposed in URL Query Parameters
- Content
View full analysis
Vulnerability Details
File Location:
src/api/search.js:59-62,src/utils/request.js:89-90, andsrc/utils/request.js:115-117
Vulnerability Type: Sensitive credential exposure through URL query strings
Risk Level: MediumThe same token-in-query pattern is also used by the comment, post, and hot API modules.
Vulnerable Code
In
src/api/search.js, the API token is inserted into the request parameter object:js const params = { _: Date.now(), token: token, };In
src/utils/request.js, these parameters are serialized directly into the URL for POST requests:js params.skill_name = skillName(); const fullPath = `${path}?${querystring.stringify(params)}`; const jsonData = JSON.stringify(data);GET requests use the same URL serialization mechanism:
js params._ = Date.now(); const fullPath = `${path}?${querystring.stringify(params)}`; const options = { host: constants.BASE_URL, path: fullPath, method: "GET", headers: { "Accept-Encoding": "identity" }, };Technical Analysis
The
GUAIKEI_API_TOKENvalue is supplied as a URL query parameter rather than through an HTTP authorization header. Although the requests use HTTPS, TLS only protects the request while it is in transit. It does not prevent the complete URL from being recorded after TLS termination.Query strings are commonly captured by:
- Web server and reverse-proxy access logs
- API gateways and load balancers
- Application performance monitoring systems
- Error-reporting and request-tracing platforms
- Network diagnostic tools
- Browser or intermediary history, where applicable
The risk is amplified by the polling design. Task creation and subsequent result queries repeatedly place the credential in request URLs. Search keywords, Douyin URLs, and other request parameters may also be recorded alongside the token.
This issue does not provide operating-system pri ...[truncated 1442 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove
tokenfrom all query parameter objects in the search, comment, post, and hot API modules. - Transmit the credential using a standard authorization header:
js const options = { host: constants.BASE_URL, path: fullPath, method: "POST", headers: { Authorization: `Bearer ${token}`, "Content-Type": "application/json", "Accept-Encoding": "identity", "Content-Length": Buffer.byteLength(jsonData), }, };- Refactor
postJson,getJson, andrequestApiso credentials are passed separately from ordinary request parameters and cannot accidentally be serialized into URLs. - Ensure reverse proxies, API gateways, application logs, and monitoring platforms redact authorization headers and sensitive query fields.
- Avoid including complete request URLs in exceptions, retry logs, or telemetry.
- Rotate existing API tokens because previously issued tokens may already be present in server or infrastructure logs.
- Apply expiration, least-privilege scope, usage limits, and anomaly monitoring to API tokens.
- Add automated tests asserting that generated request paths never contain
token,api_key,secret, or equivalent credential fields.
- Remove
