|
| 1 | +import logging |
1 | 2 | import uuid
|
2 | 3 |
|
3 | 4 | import pytest
|
@@ -121,6 +122,7 @@ def test_nosamesite_cookies_strict_no_error(iast_context_defaults):
|
121 | 122 | ("csrftoken", True),
|
122 | 123 | ("session", True),
|
123 | 124 | ("sessionid", True),
|
| 125 | + ("session_id", True), |
124 | 126 | ("a" * 31, False),
|
125 | 127 | ("b" * 32, False),
|
126 | 128 | ("c" * 33, True),
|
@@ -148,6 +150,7 @@ def test_insecure_cookies_exclusions(iast_context_defaults, cookie_name, exclude
|
148 | 150 | [
|
149 | 151 | ("session", False),
|
150 | 152 | ("sessionid", False),
|
| 153 | + ("session_id", False), |
151 | 154 | ("I love Heavy Metal", False),
|
152 | 155 | ("Dovahkiin, Dovahkiin naal ok zin los vahriin!!", False),
|
153 | 156 | ("Classic Rock is the best", False),
|
@@ -194,6 +197,62 @@ def test_insecure_cookies_deduplication_defaults(iast_context_defaults):
|
194 | 197 | _end_iast_context_and_oce()
|
195 | 198 |
|
196 | 199 |
|
| 200 | +@pytest.mark.parametrize( |
| 201 | + "regex", |
| 202 | + [ |
| 203 | + ("INVALID"), |
| 204 | + ("\n"), |
| 205 | + ], |
| 206 | +) |
| 207 | +def test_insecure_cookies_exclusions_env_var_invalid_regex(iast_context_defaults, regex): |
| 208 | + with override_global_config( |
| 209 | + dict( |
| 210 | + _iast_cookie_filter_pattern=regex, |
| 211 | + ) |
| 212 | + ): |
| 213 | + _start_iast_context_and_oce() |
| 214 | + cookies = [ |
| 215 | + {"session_id": "bar"}, |
| 216 | + {"sessionid": "bar"}, |
| 217 | + {"valid": "bar"}, |
| 218 | + ] |
| 219 | + for cookie in cookies: |
| 220 | + asm_check_cookies(cookie) |
| 221 | + |
| 222 | + span_report = _get_span_report() |
| 223 | + |
| 224 | + assert span_report is None |
| 225 | + |
| 226 | + _end_iast_context_and_oce() |
| 227 | + |
| 228 | + |
| 229 | +@pytest.mark.skip_iast_check_logs |
| 230 | +@pytest.mark.parametrize( |
| 231 | + "regex", |
| 232 | + [ |
| 233 | + ("|*"), |
| 234 | + ("\|||\\\\\\\\\\"), |
| 235 | + ], |
| 236 | +) |
| 237 | +def test_insecure_cookies_exclusions_env_var_invalid_regex_with_exception(iast_context_defaults, caplog, regex): |
| 238 | + with override_global_config( |
| 239 | + dict( |
| 240 | + _iast_cookie_filter_pattern=regex, |
| 241 | + _iast_debug=True |
| 242 | + ) |
| 243 | + ), caplog.at_level(logging.DEBUG): |
| 244 | + _start_iast_context_and_oce() |
| 245 | + cookies = {"session_id": "bar"} |
| 246 | + asm_check_cookies(cookies) |
| 247 | + |
| 248 | + span_report = _get_span_report() |
| 249 | + |
| 250 | + assert span_report is None |
| 251 | + |
| 252 | + _end_iast_context_and_oce() |
| 253 | + assert any("[IAST] Propagation error. [IAST] error in asm_check_cookies" in record.message for record in caplog.records) |
| 254 | + |
| 255 | + |
197 | 256 | def test_insecure_cookies_deduplication(iast_context_deduplication_enabled):
|
198 | 257 | _end_iast_context_and_oce()
|
199 | 258 | for num_vuln_expected in [1, 0, 0]:
|
|
0 commit comments