T09 · Insecure Skill Coding Practices
- Location
scripts/platform_client.py:13- Finding
Platform credentials and publishing metadata are transmitted over plaintext HTTP
- Content
View full analysis
str: base_url = os.environ.get("CHANJING_PLATFORM_BASE_URL", "").strip() or DEFAULT_PLATFORM_BASE_URL base_url = base_url.rstrip("/") if base_url.endswith("/api"): return base_url return f"{base_url}/api" def default_headers(content_type: str | None = None) -> dict[str, str]: platform_token = os.environ.get("CHANJING_PLATFORM_API_TOKEN", "").strip() if platform_token: headers = {"X-API-Token": platform_token} else: api_key = os.environ.get("CHANJING_PLATFORM_API_KEY", "").strip() api_secret = os.environ.get("CHANJING_PLATFORM_API_SECRET", "").strip() if not api_key or not api_secret: raise PlatformClientError(f"Platform key is not configured. {KEY_SETUP_HINT}") headers = { "X-API-Key": api_key, "X-API-Secret": api_secret, } if content_type: headers["Content-Type"] = content_type return headers ``` ```python def request_json(method: str, path: str, payload: dict | None = None): body = None headers = default_headers() if payload is not None: body = json.dumps(payload, ensure_ascii=False).encode("utf-8") headers["Content-Type"] = "application/json" request = urllib.request.Request( build_url(path), data=body, headers=headers, method=method.upper(), ) try: with urllib.request.urlopen(request) as response: return parse_response(response) ``` ...[truncated 2930 chars]- Remediation
View remediation
