T09 · Insecure Skill Coding Practices
- Location
rules/server-after-nonblocking.md:39- Finding
Raw Session Cookie Disclosed to Logging Infrastructure
- Content
View full analysis
{ const userAgent = (await headers()).get('user-agent') || 'unknown' const sessionCookie = (await cookies()).get('session-id')?.value || 'anonymous' logUserAction({ sessionCookie, userAgent }) }) ``` ### Technical Analysis The recommended example retrieves the raw value of the `session-id` cookie and passes it directly to `logUserAction`. Session identifiers are bearer credentials: possession may be sufficient to impersonate the authenticated user until the session expires or is revoked. Logging a raw session identifier is not necessary to demonstrate non-blocking execution with Next.js `after()`. It violates data-minimization and credential-handling principles. Logging systems also commonly have broader access, longer retention, replication, export, and third-party observability integrations than primary authentication systems. The repository does not define `logUserAction`, so transmission to an external network destination cannot be conclusively established. Nevertheless, the code explicitly moves sensitive authentication material into a logging abstraction, creating a concrete disclosure boundary. ### Attack Path 1. An agent follows the Skill's “correct” example when implementing a route handler. 2. An authenticated request includes a valid `session-id` cookie. 3. The route extracts the raw session identifier after processing the response. 4. `logUserAction` stores or forwards the identifier to application logs or an observability platform. 5. A user, service account, compromised integration, or attacker with log-reading access ...[truncated 780 chars]- Remediation
View remediation
