T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/main.py:103- Finding
Missing Authorization Header Bypasses Chat Endpoint Authentication
- Content
View full analysis
- Remediation
View remediation
None: if not expected_key: raise HTTPException(status_code=500, detail="Service API key is not configured") if not authorization or not authorization.startswith("Bearer "): raise HTTPException(status_code=401, detail="Authentication required") token = authorization[len("Bearer "):] if not hmac.compare_digest(token, expected_key): raise HTTPException(status_code=401, detail="Invalid API key") ``` Apply this check through a shared FastAPI dependency to every protected endpoint. Restrict network exposure using an explicit trusted bind address, reverse-proxy access controls, and firewall rules. Add tests covering missing, malformed, empty, and incorrect authorization headers. ]]>
