T09 · Insecure Skill Coding Practices
- Location
src/utils/request.js:98- Finding
API Token Exposed in URL Query Strings
- Content
View full analysis
Vulnerability Details
File Location:
src/utils/request.js:98-104, 128-135; token-bearing parameter construction also occurs insrc/api/search.js:55-62, 102-109,src/api/post.js:23-28, 50-55,src/api/comment.js:38-44, 67-72, andsrc/api/hot.js:18-22
Vulnerability Type: Credential exposure through URL query parameters
Risk Level: MediumVulnerable Code
src/utils/request.js:98-104:js params.skill_name = skillName(); const fullPath = `${path}?${querystring.stringify(params)}`; const jsonData = JSON.stringify(data); const options = { host: constants.BASE_URL,src/utils/request.js:128-135:js params._ = Date.now(); const fullPath = `${path}?${querystring.stringify(params)}`; const options = { host: constants.BASE_URL, path: fullPath, method: "GET", headers: { "Accept-Encoding": "identity" },Representative token construction in
src/api/search.js:55-62:js const params = { _: Date.now(), token: token, }; const data = { keyword, sort_type: sort,Technical Analysis
The API token is inserted into the
paramsobject and serialized directly into the request URL byquerystring.stringify(params). This occurs for both GET requests and POST requests. Consequently, requests contain URLs such as:text /api/douyin/general-search/info?...&token=API_TOKENHTTPS protects the request while it is in transit, but it does not prevent the complete URL from being recorded by the destination server, reverse proxies, API gateways, load balancers, observability platforms, debugging tools, or error telemetry. URL query strings are routinely retained in access logs, whereas authorization headers can be handled using established credential-redaction controls.
The API hostname is fixed to
www.guaikei.com, so this is not an SSRF issue. The vulnerability is the unnecessary exposure and propagation of a reusable c ...[truncated 1248 chars]- Remediation
View remediation
Remediation Suggestions
-
Remove the token from all URL parameter objects.
-
Send it through a standard authorization header, for example:
js headers: { Authorization: `Bearer ${token}`, "Content-Type": "application/json", "Accept-Encoding": "identity", } -
Refactor
getJson,postJson, andrequestApiso credentials are accepted separately from ordinary query parameters and cannot be accidentally serialized into URLs. -
Ensure server, proxy, gateway, and telemetry configurations redact authorization headers and any legacy
tokenquery parameter. -
Rotate tokens that may previously have appeared in access or observability logs.
-
Apply server-side expiration, least-privilege scopes, usage limits, and anomaly detection to reduce the effect of credential theft.
-
Add automated tests asserting that generated request paths never contain
token,api_key, or other credential fields.
-
