T09 · Insecure Skill Coding Practices
- Location
rules/server-after-nonblocking.md:44- Finding
Raw Session Credential Passed to Logging Function
- Content
View full analysis
{ const userAgent = (await headers()).get('user-agent') || 'unknown' const sessionCookie = (await cookies()).get('session-id')?.value || 'anonymous' logUserAction({ sessionCookie, userAgent }) }) ``` ### Technical Analysis The recommended code reads the complete value of the `session-id` authentication cookie and passes it to `logUserAction`. Session cookies are bearer credentials: possession may be sufficient to impersonate the associated user until the session expires or is revoked. Logging infrastructure commonly has broader access, replication, retention, backup, and export paths than authentication infrastructure. Consequently, recording raw session tokens unnecessarily expands the credential's exposure surface. The implementation of `logUserAction` is not included, so transmission to an external service is not established; however, the example explicitly directs a sensitive credential into a logging path. ### Attack Path 1. An authenticated user invokes the demonstrated route. 2. The server retrieves the user's raw `session-id` cookie. 3. The complete cookie value is passed to `logUserAction`. 4. The logging implementation stores or forwards the supplied field. 5. An attacker with access to application logs, log exports, backups, or a connected logging platform obtains the token. 6. If the session remains valid and lacks additional binding controls, the attacker replays the token to impersonate the user. ### Impact Assessment Successful exploitation could allow session hijacking with the privileges of the affected user. The scope depends on the compromised account and may include access to private user data or privileged administrative functionality. Exposure may affect every authenticated request process ...[truncated 133 chars]- Remediation
View remediation
