nuclei-templates/http/token-spray/api-npm.yaml

30 lines
667 B
YAML

id: api-npm
info:
name: NPM API Test
author: zzeitlin
severity: info
reference:
- https://docs.npmjs.com/creating-and-viewing-access-tokens
metadata:
max-request: 1
tags: token-spray,node,npm
self-contained: true
http:
- method: GET
path:
- "https://registry.npmjs.org/-/whoami"
headers:
Authorization: Bearer {{token}}
matchers:
- type: status
status:
- 401
- 403
negative: true
# digest: 4a0a00473045022057be80c1e2ae7c8da088ffc2e109095690a3b333ed148cb7c0d3ebb41859c9ac022100968578a69a2226a9117634bc5534e63a92150c0e3606b29ed93de9def127527f:922c64590222798bb761d5b6d8e72950