T09 · Insecure Skill Coding Practices
- Location
src/api/server.ts:23- Finding
Unauthenticated Sidecar API Exposes and Modifies Sensitive Manager State
- Content
View full analysis
{ const runtime = await bootstrapManagerRuntime(); const app = express(); app.use(express.json({ limit: '1mb' })); app.get('/health', healthHandler(runtime.store)); app.get('/sessions', async (_req: Request, res: Response) => { res.json(await runtime.sessionService.listSessions()); }); ``` Representative state-changing endpoints are also registered without authentication or authorization: ```ts app.post('/sessions/:id/checkpoint', async (req: Request, res: Response) => { const result = await runtime.sessionService.checkpoint(String(req.params.id), req.body || {}); await runtime.attentionService.refresh(await runtime.sessionService.listSessions()); res.json(result); }); app.post('/sessions/:id/close', async (req: Request, res: Response) => { const session = await runtime.sessionService.close( String(req.params.id), (req.body || {}) as CloseSessionInput ); const fact = await runtime.capabilityFactService.createFromClosure(session, req.body || {}); const snapshot = await runtime.shareService.createSnapshot(session, 'capability_snapshot', { fact_id: fact.fact_id, }); await runtime.attentionService.refresh(await runtime.sessionService.listSessions()); res.json({ session, capability_fact: fact, snapshot, }); }); app.post('/inbound-message', inboundHandler(runtime.shadowService)); ``` The server may explicitly be exposed on all interfaces: ```ts export const resolveBindHost = () => { const configured = (process.env.OPENCLAW_MANAGER_BIND_HOST || DEFAULT_SIDECAR_HOST).trim(); const normalized = normalizeHost(configured); if (is ...[truncated 2704 chars]- Remediation
View remediation
` header on every route except a minimal liveness endpoint. 3. Compare tokens with a timing-safe operation and never place tokens in URLs or logs. 4. Introduce authorization checks for sensitive operations such as session closure, connector ingestion, thread promotion, and evidence export. 5. Refuse `0.0.0.0` and `::` binding unless strong authentication has been configured and explicitly acknowledged. 6. Prefer a Unix-domain socket with restrictive filesystem permissions for local-only deployments where supported. 7. Apply rate limiting, request auditing, and conservative request-size limits. 8. If browser clients are supported, configure a strict origin policy and CSRF protection rather than treating loopback as authentication. 9. Add automated tests verifying that anonymous requests to every non-health endpoint receive `401 Unauthorized` or `403 Forbidden`. ]]>
