Skip to content

Commit

Permalink
chore(iast): taint parameter name and header name in fastapi
Browse files Browse the repository at this point in the history
  • Loading branch information
avara1986 committed Jan 23, 2025
1 parent ff41c13 commit 2729de4
Show file tree
Hide file tree
Showing 2 changed files with 13 additions and 1 deletion.
2 changes: 1 addition & 1 deletion ddtrace/appsec/_iast/_handlers.py
Original file line number Diff line number Diff line change
Expand Up @@ -319,7 +319,7 @@ def if_iast_taint_starlette_datastructures(origin, wrapped, instance, args, kwar
res.append(
taint_pyobject(
pyobject=element,
source_name=origin_to_str(origin),
source_name=element,
source_value=element,
source_origin=origin,
)
Expand Down
12 changes: 12 additions & 0 deletions tests/contrib/fastapi/test_fastapi_appsec_iast.py
Original file line number Diff line number Diff line change
Expand Up @@ -120,6 +120,8 @@ async def test_route(request: Request):
"ranges_start": ranges_result[0].start,
"ranges_length": ranges_result[0].length,
"ranges_origin": origin_to_str(ranges_result[0].source.origin),
"ranges_origin_name": ranges_result[0].source.name,
"ranges_origin_value": ranges_result[0].source.value,
}
)

Expand All @@ -137,6 +139,8 @@ async def test_route(request: Request):
assert result["ranges_start"] == 0
assert result["ranges_length"] == 15
assert result["ranges_origin"] == "http.request.parameter.name"
assert result["ranges_origin_name"] == "iast_queryparam"
assert result["ranges_origin_value"] == "iast_queryparam"


def test_query_param_name_source_post(fastapi_application, client, tracer, test_spans):
Expand All @@ -153,6 +157,8 @@ async def test_route(request: Request):
"ranges_start": ranges_result[0].start,
"ranges_length": ranges_result[0].length,
"ranges_origin": origin_to_str(ranges_result[0].source.origin),
"ranges_origin_name": ranges_result[0].source.name,
"ranges_origin_value": ranges_result[0].source.value,
}
)

Expand All @@ -170,6 +176,8 @@ async def test_route(request: Request):
assert result["ranges_start"] == 0
assert result["ranges_length"] == 15
assert result["ranges_origin"] == "http.request.parameter.name"
assert result["ranges_origin_name"] == "iast_queryparam"
assert result["ranges_origin_value"] == "iast_queryparam"


def test_header_value_source(fastapi_application, client, tracer, test_spans):
Expand Down Expand Up @@ -217,6 +225,8 @@ async def test_route(request: Request):
"ranges_start": ranges_result[0].start,
"ranges_length": ranges_result[0].length,
"ranges_origin": origin_to_str(ranges_result[0].source.origin),
"ranges_origin_name": ranges_result[0].source.name,
"ranges_origin_value": ranges_result[0].source.value,
}
)

Expand All @@ -234,6 +244,8 @@ async def test_route(request: Request):
assert result["ranges_start"] == 0
assert result["ranges_length"] == 11
assert result["ranges_origin"] == "http.request.header.name"
assert result["ranges_origin_name"] == "iast_header"
assert result["ranges_origin_value"] == "iast_header"


@pytest.mark.skipif(sys.version_info < (3, 9), reason="typing.Annotated was introduced on 3.9")
Expand Down

0 comments on commit 2729de4

Please sign in to comment.