-
Notifications
You must be signed in to change notification settings - Fork 58
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update disallowed_csp_hostnames.py, also trigger on higher level denied domains #3980
base: main
Are you sure you want to change the base?
Conversation
…ed domains If a subdomain of a denied domain is listed, we should warn. Eg, if www.badexample.com is used in the CSP, but badexample.com is listed we should trigger.
Quality Gate passedIssues Measures |
This PR has been ported to feature/nibbles see 15304bc. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Perhaps a generator and unit test to provide an example would make this a bit more clear (or the comment suggestion)
hostnameparts = hostname.lower().split(".") | ||
for i in range(len(hostnameparts)): | ||
if ".".join(hostnameparts[i:]) in disallowed_domains: | ||
ft = KATFindingType(id="KAT-DISALLOWED-DOMAIN-IN-CSP") | ||
f = Finding(ooi=input_ooi.reference, finding_type=ft.reference) | ||
yield ft | ||
yield f | ||
break |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
hostnameparts = hostname.lower().split(".") | |
for i in range(len(hostnameparts)): | |
if ".".join(hostnameparts[i:]) in disallowed_domains: | |
ft = KATFindingType(id="KAT-DISALLOWED-DOMAIN-IN-CSP") | |
f = Finding(ooi=input_ooi.reference, finding_type=ft.reference) | |
yield ft | |
yield f | |
break | |
hostnameparts = hostname.lower().split(".") | |
# For e.g. ["www", "example", "com"], check "www.example.com", "example.com" and "com" | |
for i in range(len(hostnameparts)): | |
if ".".join(hostnameparts[i:]) in disallowed_domains: | |
ft = KATFindingType(id="KAT-DISALLOWED-DOMAIN-IN-CSP") | |
f = Finding(ooi=input_ooi.reference, finding_type=ft.reference) | |
yield ft | |
yield f | |
break |
If a subdomain of a denied domain is listed, we should warn. Eg, if www.badexample.com is used in the CSP, but badexample.com is listed we should trigger.
Changes
Loops over the parts of the listed hostname, and looks for the parent domains to check if they are listed.
Issue link
You have to create an issue to link to this PR. If this really is not possible, write a very detailed description here and add this PR to the project board directly.
Please add the link to the issue after "Closes".
Closes #3979
Demo
Please add some proof in the form of screenshots or screen recordings to show (off) new functionality, if there are interesting new features for end-users.
QA notes
Please add some information for QA on how to test the newly created code.
Code Checklist
.env
changes files if required and changed the.env-dist
accordingly.Checklist for code reviewers:
Copy-paste the checklist from the docs/source/templates folder into your comment.
Checklist for QA:
Copy-paste the checklist from the docs/source/templates folder into your comment.