T09 · Insecure Skill Coding Practices
- Location
src/api.py:329- Finding
Session Cookies Can Be Transmitted over Plaintext HTTP
- Content
View full analysis
- Remediation
View remediation
`. 3. Do not attach authentication to arbitrary caller-provided URLs. Parse the document identifier and reconstruct the URL from the trusted constant `https://docs.qq.com`. 4. Disable automatic redirects for authenticated requests or manually validate every redirect destination before following it. 5. Use a `requests.Session` with properly scoped secure cookies rather than manually constructing a raw `Cookie` header. 6. Add regression tests confirming rejection of: - `http://docs.qq.com/...` - `https://docs.qq.com:444/...` - `https://user@example.com@docs.qq.com/...` - URLs with unauthorized hosts or paths ]]>
