T09 · Insecure Skill Coding Practices
- Location
scripts/common.py:84- Finding
Bearer API Key Can Be Transmitted Over an Insecure or Unintended Transport
- Content
View full analysis
str: base_url = (cli_base_url or "").strip() or _require_env_var(RAGFLOW_API_URL_ENV) parsed = urllib.parse.urlsplit(base_url) if not parsed.scheme or not parsed.netloc: raise ConfigError( f"Invalid {RAGFLOW_API_URL_ENV}. Use an absolute URL such as http://127.0.0.1:9380." ) return base_url.rstrip("/") ``` ```python def request_json( url: str, api_key: str, *, method: str = "GET", body: bytes | None = None, content_type: str | None = None, accept: str = "application/json", ) -> dict[str, Any]: headers = {"Authorization": f"Bearer {api_key}"} if accept: headers["Accept"] = accept if content_type: headers["Content-Type"] = content_type request_obj = urllib.request.Request(url, headers=headers, data=body, method=method) try: with urllib.request.urlopen(request_obj, timeout=HTTP_TIMEOUT) as response: return decode_json_response(response.read()) ``` ### Technical Analysis The base URL validator only checks that the supplied value contains a scheme and network location. It does not restrict the scheme to HTTP or HTTPS, require TLS for remote hosts, reject embedded user information, or constrain the destination to an expected RAGFlow host. After this minimal validation, every request adds the RAGFlow API key to the `Authorization` header as a Bearer token. Therefore, a plaintext remote URL such as `http://attacker-controlled.example` would receive the API key without transport encryption. The documentat ...[truncated 1579 chars]- Remediation
View remediation
