mirror of
https://github.com/prowler-cloud/prowler.git
synced 2026-10-09 21:14:22 +00:00
feat(cognito): Add new checks related with cognito service (#3898)
This commit is contained in:
+106
@@ -0,0 +1,106 @@
|
||||
from unittest import mock
|
||||
|
||||
from prowler.providers.aws.services.cognito.cognito_service import (
|
||||
IdentityPool,
|
||||
IdentityPoolRoles,
|
||||
)
|
||||
from tests.providers.aws.utils import AWS_ACCOUNT_NUMBER, AWS_REGION_US_EAST_1
|
||||
|
||||
|
||||
class Test_cognito_identity_pool_guest_access_disabled:
|
||||
def test_cognito_no_identity_pools(self):
|
||||
cognito_identity_client = mock.MagicMock
|
||||
cognito_identity_client.identity_pools = {}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIdentity",
|
||||
cognito_identity_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_identity_client.cognito_identity_client",
|
||||
new=cognito_identity_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_identity_pool_guest_access_disabled.cognito_identity_pool_guest_access_disabled import (
|
||||
cognito_identity_pool_guest_access_disabled,
|
||||
)
|
||||
|
||||
check = cognito_identity_pool_guest_access_disabled()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 0
|
||||
|
||||
def test_cognito_identity_pools_guest_access_disabled(self):
|
||||
cognito_identity_client = mock.MagicMock
|
||||
identity_pool_arn = f"arn:aws:cognito-identity:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:identitypool/eu-west-1_123456789"
|
||||
identity_pool_name = "identity_pool_name"
|
||||
identity_pool_id = "eu-west-1_123456789"
|
||||
cognito_identity_client.identity_pools = {
|
||||
identity_pool_arn: IdentityPool(
|
||||
allow_unauthenticated_identities=False,
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=identity_pool_id,
|
||||
arn=identity_pool_arn,
|
||||
name=identity_pool_name,
|
||||
)
|
||||
}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIdentity",
|
||||
cognito_identity_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_identity_client.cognito_identity_client",
|
||||
new=cognito_identity_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_identity_pool_guest_access_disabled.cognito_identity_pool_guest_access_disabled import (
|
||||
cognito_identity_pool_guest_access_disabled,
|
||||
)
|
||||
|
||||
check = cognito_identity_pool_guest_access_disabled()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "PASS"
|
||||
assert (
|
||||
result[0].status_extended
|
||||
== f"Identity pool {identity_pool_id} has guest access disabled."
|
||||
)
|
||||
|
||||
assert result[0].resource_id == identity_pool_id
|
||||
assert result[0].resource_arn == identity_pool_arn
|
||||
|
||||
def test_cognito_identity_pools_guest_access_enabled(self):
|
||||
cognito_identity_client = mock.MagicMock
|
||||
identity_pool_arn = f"arn:aws:cognito-identity:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:identitypool/eu-west-1_123456789"
|
||||
identity_pool_name = "identity_pool_name"
|
||||
identity_pool_id = "eu-west-1_123456789"
|
||||
unauthenticated_role = "unauthenticated_role"
|
||||
cognito_identity_client.identity_pools = {
|
||||
identity_pool_arn: IdentityPool(
|
||||
allow_unauthenticated_identities=True,
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=identity_pool_id,
|
||||
arn=identity_pool_arn,
|
||||
name=identity_pool_name,
|
||||
roles=IdentityPoolRoles(unauthenticated=unauthenticated_role),
|
||||
)
|
||||
}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIdentity",
|
||||
cognito_identity_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_identity_client.cognito_identity_client",
|
||||
new=cognito_identity_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_identity_pool_guest_access_disabled.cognito_identity_pool_guest_access_disabled import (
|
||||
cognito_identity_pool_guest_access_disabled,
|
||||
)
|
||||
|
||||
check = cognito_identity_pool_guest_access_disabled()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "FAIL"
|
||||
assert (
|
||||
result[0].status_extended
|
||||
== f"Identity pool {identity_pool_name} has guest access enabled assuming the role {unauthenticated_role}."
|
||||
)
|
||||
|
||||
assert result[0].resource_id == identity_pool_id
|
||||
assert result[0].resource_arn == identity_pool_arn
|
||||
@@ -1,7 +1,16 @@
|
||||
import mock
|
||||
from boto3 import client
|
||||
from moto import mock_aws
|
||||
|
||||
from prowler.providers.aws.services.cognito.cognito_service import CognitoIDP
|
||||
from prowler.providers.aws.services.cognito.cognito_service import (
|
||||
AccountTakeoverRiskConfiguration,
|
||||
CognitoIdentity,
|
||||
CognitoIDP,
|
||||
CompromisedCredentialsRiskConfiguration,
|
||||
IdentityPoolRoles,
|
||||
RiskConfiguration,
|
||||
UserPoolClient,
|
||||
)
|
||||
from tests.providers.aws.utils import (
|
||||
AWS_ACCOUNT_NUMBER,
|
||||
AWS_REGION_EU_WEST_1,
|
||||
@@ -13,7 +22,7 @@ from tests.providers.aws.utils import (
|
||||
class Test_Cognito_Service:
|
||||
# Test Cognito Service
|
||||
@mock_aws
|
||||
def test_service(self):
|
||||
def test_service_idp(self):
|
||||
aws_provider = set_mocked_aws_provider(
|
||||
audited_regions=[AWS_REGION_EU_WEST_1, AWS_REGION_US_EAST_1]
|
||||
)
|
||||
@@ -22,7 +31,7 @@ class Test_Cognito_Service:
|
||||
|
||||
# Test Cognito client
|
||||
@mock_aws
|
||||
def test_client(self):
|
||||
def test_client_idp(self):
|
||||
aws_provider = set_mocked_aws_provider(
|
||||
audited_regions=[AWS_REGION_EU_WEST_1, AWS_REGION_US_EAST_1]
|
||||
)
|
||||
@@ -32,7 +41,7 @@ class Test_Cognito_Service:
|
||||
|
||||
# Test Cognito session
|
||||
@mock_aws
|
||||
def test__get_session__(self):
|
||||
def test__get_session_idp__(self):
|
||||
aws_provider = set_mocked_aws_provider(
|
||||
audited_regions=[AWS_REGION_EU_WEST_1, AWS_REGION_US_EAST_1]
|
||||
)
|
||||
@@ -41,7 +50,7 @@ class Test_Cognito_Service:
|
||||
|
||||
# Test Cognito Session
|
||||
@mock_aws
|
||||
def test_audited_account(self):
|
||||
def test_audited_account_idp(self):
|
||||
aws_provider = set_mocked_aws_provider(
|
||||
audited_regions=[AWS_REGION_EU_WEST_1, AWS_REGION_US_EAST_1]
|
||||
)
|
||||
@@ -87,6 +96,112 @@ class Test_Cognito_Service:
|
||||
assert user_pool.deletion_protection is not None
|
||||
assert user_pool.advanced_security_mode is not None
|
||||
assert user_pool.tags is not None
|
||||
assert user_pool.account_recovery_settings is not None
|
||||
assert user_pool.tags is not None
|
||||
|
||||
@mock_aws
|
||||
def test_list_user_pool_clients(self):
|
||||
cognito_client = mock.MagicMock()
|
||||
user_pool_arn = "user_pool_test_1"
|
||||
cognito_client[user_pool_arn].id = "user_pool_id"
|
||||
cognito_client[user_pool_arn].arn = user_pool_arn
|
||||
cognito_client[user_pool_arn].name = "user_pool_name"
|
||||
cognito_client[user_pool_arn].region = "eu-west-1"
|
||||
cognito_client[user_pool_arn].user_pool_clients["user_pool_client_id"] = (
|
||||
UserPoolClient(
|
||||
id="user_pool_client_id",
|
||||
name="user_pool_client_name",
|
||||
arn=f"{user_pool_arn}/client/user_pool_client_id",
|
||||
region="eu-west-1",
|
||||
)
|
||||
)
|
||||
|
||||
with mock.patch(
|
||||
"prowler.providers.common.common.get_global_provider",
|
||||
return_value=set_mocked_aws_provider(),
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
for user_pool in cognito_client.user_pools.values():
|
||||
assert user_pool.region == "eu-west-1"
|
||||
assert user_pool.name == "user_pool_name"
|
||||
assert user_pool.id == "user_pool_id"
|
||||
assert (
|
||||
user_pool.user_pool_clients["user_pool_client_id"].id
|
||||
== "user_pool_client_id"
|
||||
)
|
||||
assert (
|
||||
user_pool.user_pool_clients["user_pool_client_id"].name
|
||||
== "user_pool_client_name"
|
||||
)
|
||||
assert (
|
||||
user_pool.user_pool_clients["user_pool_client_id"].region
|
||||
== "eu-west-1"
|
||||
)
|
||||
assert (
|
||||
user_pool.user_pool_clients["user_pool_client_id"].arn
|
||||
== f"{user_pool_arn}/client/user_pool_client_id"
|
||||
)
|
||||
|
||||
@mock_aws
|
||||
def test_describe_user_pool_clients(self):
|
||||
cognito_client = mock.MagicMock()
|
||||
user_pool_arn = "user_pool_test_1"
|
||||
cognito_client[user_pool_arn].id = "user_pool_id"
|
||||
cognito_client[user_pool_arn].arn = user_pool_arn
|
||||
cognito_client[user_pool_arn].name = "user_pool_name"
|
||||
cognito_client[user_pool_arn].region = "eu-west-1"
|
||||
cognito_client[user_pool_arn].user_pool_clients["user_pool_client_id"] = (
|
||||
UserPoolClient(
|
||||
id="user_pool_client_id",
|
||||
name="user_pool_client_name",
|
||||
region="eu-west-1",
|
||||
arn=f"{user_pool_arn}/client/user_pool_client_id",
|
||||
prevent_user_existence_errors="ENABLED",
|
||||
enable_token_revocation=True,
|
||||
)
|
||||
)
|
||||
|
||||
with mock.patch(
|
||||
"prowler.providers.common.common.get_global_provider",
|
||||
return_value=set_mocked_aws_provider(),
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
for user_pool in cognito_client.user_pools.values():
|
||||
assert user_pool.region == "eu-west-1"
|
||||
assert user_pool.name == "user_pool_name"
|
||||
assert user_pool.id == "user_pool_id"
|
||||
assert (
|
||||
user_pool.user_pool_clients["user_pool_client_id"].id
|
||||
== "user_pool_client_id"
|
||||
)
|
||||
assert (
|
||||
user_pool.user_pool_clients["user_pool_client_id"].name
|
||||
== "user_pool_client_name"
|
||||
)
|
||||
assert (
|
||||
user_pool.user_pool_clients["user_pool_client_id"].region
|
||||
== "eu-west-1"
|
||||
)
|
||||
assert (
|
||||
user_pool.user_pool_clients["user_pool_client_id"].arn
|
||||
== f"{user_pool_arn}/client/user_pool_client_id"
|
||||
)
|
||||
assert (
|
||||
user_pool.user_pool_clients[
|
||||
"user_pool_client_id"
|
||||
].prevent_user_existence_errors
|
||||
== "ENABLED"
|
||||
)
|
||||
assert (
|
||||
user_pool.user_pool_clients[
|
||||
"user_pool_client_id"
|
||||
].enable_token_revocation
|
||||
is True
|
||||
)
|
||||
|
||||
@mock_aws
|
||||
def test_get_user_pool_mfa_config(self):
|
||||
@@ -115,3 +230,169 @@ class Test_Cognito_Service:
|
||||
"Enabled": True
|
||||
}
|
||||
assert user_pool.mfa_config.status == "ON"
|
||||
|
||||
def test_get_user_pool_risk_configuration(self):
|
||||
cognito_client = mock.MagicMock()
|
||||
user_pool_arn = "user_pool_test_1"
|
||||
cognito_client.user_pools[user_pool_arn].id = "user_pool_id"
|
||||
cognito_client.user_pools[user_pool_arn].arn = user_pool_arn
|
||||
cognito_client.user_pools[user_pool_arn].name = "user_pool_name"
|
||||
cognito_client.user_pools[user_pool_arn].region = "eu-west-1"
|
||||
cognito_client.user_pools[user_pool_arn].risk_configuration = RiskConfiguration(
|
||||
compromised_credentials_risk_configuration=CompromisedCredentialsRiskConfiguration(
|
||||
event_filter=["PASSWORD_CHANGE", "SIGN_UP", "SIGN_IN"],
|
||||
actions="BLOCK",
|
||||
),
|
||||
account_takeover_risk_configuration=AccountTakeoverRiskConfiguration(
|
||||
low_action="BLOCK",
|
||||
medium_action="BLOCK",
|
||||
high_action="BLOCK",
|
||||
),
|
||||
)
|
||||
|
||||
with mock.patch(
|
||||
"prowler.providers.common.common.get_global_provider",
|
||||
return_value=set_mocked_aws_provider(),
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
for user_pool in cognito_client.user_pools.values():
|
||||
assert user_pool.region == "eu-west-1"
|
||||
assert user_pool.name == "user_pool_name"
|
||||
assert user_pool.id == "user_pool_id"
|
||||
assert (
|
||||
user_pool.risk_configuration.compromised_credentials_risk_configuration
|
||||
== CompromisedCredentialsRiskConfiguration(
|
||||
event_filter=["PASSWORD_CHANGE", "SIGN_UP", "SIGN_IN"],
|
||||
actions="BLOCK",
|
||||
)
|
||||
)
|
||||
assert (
|
||||
user_pool.risk_configuration.account_takeover_risk_configuration.low_action
|
||||
== "BLOCK"
|
||||
)
|
||||
assert (
|
||||
user_pool.risk_configuration.account_takeover_risk_configuration.medium_action
|
||||
== "BLOCK"
|
||||
)
|
||||
assert (
|
||||
user_pool.risk_configuration.account_takeover_risk_configuration.high_action
|
||||
== "BLOCK"
|
||||
)
|
||||
|
||||
@mock_aws
|
||||
def test_service_identity(self):
|
||||
aws_provider = set_mocked_aws_provider(
|
||||
audited_regions=[AWS_REGION_EU_WEST_1, AWS_REGION_US_EAST_1]
|
||||
)
|
||||
cognito = CognitoIdentity(aws_provider)
|
||||
assert cognito.service == "cognito-identity"
|
||||
|
||||
# Test Cognito client
|
||||
@mock_aws
|
||||
def test_client_identity(self):
|
||||
aws_provider = set_mocked_aws_provider(
|
||||
audited_regions=[AWS_REGION_EU_WEST_1, AWS_REGION_US_EAST_1]
|
||||
)
|
||||
cognito = CognitoIdentity(aws_provider)
|
||||
for regional_client in cognito.regional_clients.values():
|
||||
assert regional_client.__class__.__name__ == "CognitoIdentity"
|
||||
|
||||
# Test Cognito session
|
||||
@mock_aws
|
||||
def test__get_session_identity__(self):
|
||||
aws_provider = set_mocked_aws_provider(
|
||||
audited_regions=[AWS_REGION_EU_WEST_1, AWS_REGION_US_EAST_1]
|
||||
)
|
||||
cognito = CognitoIdentity(aws_provider)
|
||||
assert cognito.session.__class__.__name__ == "Session"
|
||||
|
||||
# Test Cognito Session
|
||||
@mock_aws
|
||||
def test_audited_account_identity(self):
|
||||
aws_provider = set_mocked_aws_provider(
|
||||
audited_regions=[AWS_REGION_EU_WEST_1, AWS_REGION_US_EAST_1]
|
||||
)
|
||||
cognito = CognitoIdentity(aws_provider)
|
||||
assert cognito.audited_account == AWS_ACCOUNT_NUMBER
|
||||
|
||||
@mock_aws
|
||||
def test_list_identity_pools(self):
|
||||
identity_pool_name_1 = "identity_pool_test_1"
|
||||
identity_pool_name_2 = "identity_pool_test_2"
|
||||
aws_provider = set_mocked_aws_provider(
|
||||
audited_regions=[AWS_REGION_EU_WEST_1, AWS_REGION_US_EAST_1]
|
||||
)
|
||||
cognito_client_eu_west_1 = client("cognito-identity", region_name="eu-west-1")
|
||||
cognito_client_us_east_1 = client("cognito-identity", region_name="us-east-1")
|
||||
cognito_client_eu_west_1.create_identity_pool(
|
||||
IdentityPoolName=identity_pool_name_1, AllowUnauthenticatedIdentities=True
|
||||
)
|
||||
cognito_client_us_east_1.create_identity_pool(
|
||||
IdentityPoolName=identity_pool_name_2, AllowUnauthenticatedIdentities=True
|
||||
)
|
||||
cognito = CognitoIdentity(aws_provider)
|
||||
assert len(cognito.identity_pools) == 2
|
||||
for identity_pool in cognito.identity_pools.values():
|
||||
assert (
|
||||
identity_pool.name == identity_pool_name_1
|
||||
or identity_pool.name == identity_pool_name_2
|
||||
)
|
||||
assert (
|
||||
identity_pool.region == "eu-west-1"
|
||||
or identity_pool.region == "us-east-1"
|
||||
)
|
||||
|
||||
@mock_aws
|
||||
def test_describe_identity_pools(self):
|
||||
identity_pool_name_1 = "identity_pool_test_1"
|
||||
aws_provider = set_mocked_aws_provider(
|
||||
audited_regions=[AWS_REGION_EU_WEST_1, AWS_REGION_US_EAST_1]
|
||||
)
|
||||
cognito_client_eu_west_1 = client("cognito-identity", region_name="eu-west-1")
|
||||
identity_pool_id = cognito_client_eu_west_1.create_identity_pool(
|
||||
IdentityPoolName=identity_pool_name_1, AllowUnauthenticatedIdentities=True
|
||||
)["IdentityPoolId"]
|
||||
cognito = CognitoIdentity(aws_provider)
|
||||
assert len(cognito.identity_pools) == 1
|
||||
for identity_pool in cognito.identity_pools.values():
|
||||
assert identity_pool.name == identity_pool_name_1
|
||||
assert identity_pool.region == "eu-west-1"
|
||||
assert identity_pool.id == identity_pool_id
|
||||
assert identity_pool.associated_pools is not None
|
||||
assert identity_pool.tags is not None
|
||||
assert identity_pool.allow_unauthenticated_identities is not None
|
||||
|
||||
@mock_aws
|
||||
def test_get_identity_pool_tags(self):
|
||||
cognito_identity_client = mock.MagicMock()
|
||||
identity_pool_arn = "identity_pool_test_1"
|
||||
cognito_identity_client[identity_pool_arn].id = "identity_pool_id"
|
||||
cognito_identity_client[identity_pool_arn].arn = identity_pool_arn
|
||||
cognito_identity_client[identity_pool_arn].name = "identity_pool_name"
|
||||
cognito_identity_client[identity_pool_arn].region = "eu-west-1"
|
||||
cognito_identity_client[identity_pool_arn].tags = {"tag_key": "tag_value"}
|
||||
cognito_identity_client[identity_pool_arn].allow_unauthenticated_identities = (
|
||||
True
|
||||
)
|
||||
cognito_identity_client[identity_pool_arn].roles = IdentityPoolRoles(
|
||||
authenticated="authenticated_role",
|
||||
unauthenticated="unauthenticated_role",
|
||||
)
|
||||
|
||||
with mock.patch(
|
||||
"prowler.providers.common.common.get_global_provider",
|
||||
return_value=set_mocked_aws_provider(),
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_identity_client.cognito_identity_client",
|
||||
new=cognito_identity_client,
|
||||
):
|
||||
for identity_pool in cognito_identity_client.identity_pools.values():
|
||||
assert identity_pool.region == "eu-west-1"
|
||||
assert identity_pool.name == "identity_pool_name"
|
||||
assert identity_pool.id == "identity_pool_id"
|
||||
assert identity_pool.tags == {"tag_key": "tag_value"}
|
||||
assert identity_pool.allow_unauthenticated_identities is True
|
||||
assert identity_pool.roles.authenticated == "authenticated_role"
|
||||
assert identity_pool.roles.unauthenticated == "unauthenticated_role"
|
||||
|
||||
+146
@@ -0,0 +1,146 @@
|
||||
from datetime import datetime
|
||||
from unittest import mock
|
||||
|
||||
from prowler.providers.aws.services.cognito.cognito_service import UserPool
|
||||
from tests.providers.aws.utils import AWS_ACCOUNT_NUMBER, AWS_REGION_US_EAST_1
|
||||
|
||||
|
||||
class Test_cognito_user_pool_advanced_security_enabled:
|
||||
def test_cognito_no_user_pools(self):
|
||||
cognito_client = mock.MagicMock
|
||||
cognito_client.user_pools = {}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_advanced_security_enabled.cognito_user_pool_advanced_security_enabled import (
|
||||
cognito_user_pool_advanced_security_enabled,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_advanced_security_enabled()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 0
|
||||
|
||||
def test_cognito_user_pools_advanced_security_off(self):
|
||||
cognito_client = mock.MagicMock
|
||||
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
|
||||
user_pool_name = "user_pool_name"
|
||||
user_pool_id = "eu-west-1_123456789"
|
||||
cognito_client.user_pools = {
|
||||
user_pool_arn: UserPool(
|
||||
advanced_security_mode="OFF",
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=user_pool_id,
|
||||
arn=user_pool_arn,
|
||||
name=user_pool_name,
|
||||
last_modified=datetime.now(),
|
||||
creation_date=datetime.now(),
|
||||
status="ACTIVE",
|
||||
)
|
||||
}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_advanced_security_enabled.cognito_user_pool_advanced_security_enabled import (
|
||||
cognito_user_pool_advanced_security_enabled,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_advanced_security_enabled()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "FAIL"
|
||||
assert result[0].status_extended == (
|
||||
f"User pool {user_pool_name} has advanced security disabled."
|
||||
)
|
||||
|
||||
assert result[0].resource_id == user_pool_id
|
||||
assert result[0].resource_arn == user_pool_arn
|
||||
|
||||
def test_cognito_user_pools_advanced_security_audit(self):
|
||||
cognito_client = mock.MagicMock
|
||||
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
|
||||
user_pool_name = "user_pool_name"
|
||||
user_pool_id = "eu-west-1_123456789"
|
||||
cognito_client.user_pools = {
|
||||
user_pool_arn: UserPool(
|
||||
advanced_security_mode="AUDIT",
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=user_pool_id,
|
||||
arn=user_pool_arn,
|
||||
name=user_pool_name,
|
||||
last_modified=datetime.now(),
|
||||
creation_date=datetime.now(),
|
||||
status="ACTIVE",
|
||||
)
|
||||
}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_advanced_security_enabled.cognito_user_pool_advanced_security_enabled import (
|
||||
cognito_user_pool_advanced_security_enabled,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_advanced_security_enabled()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "FAIL"
|
||||
assert result[0].status_extended == (
|
||||
f"User pool {user_pool_name} has advanced security enabled but with audit-only mode."
|
||||
)
|
||||
|
||||
assert result[0].resource_id == user_pool_id
|
||||
assert result[0].resource_arn == user_pool_arn
|
||||
|
||||
def test_cognito_user_pools_advanced_security_enforced(self):
|
||||
cognito_client = mock.MagicMock
|
||||
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
|
||||
user_pool_name = "user_pool_name"
|
||||
user_pool_id = "eu-west-1_123456789"
|
||||
cognito_client.user_pools = {
|
||||
user_pool_arn: UserPool(
|
||||
advanced_security_mode="ENFORCED",
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=user_pool_id,
|
||||
arn=user_pool_arn,
|
||||
name=user_pool_name,
|
||||
last_modified=datetime.now(),
|
||||
creation_date=datetime.now(),
|
||||
status="ACTIVE",
|
||||
)
|
||||
}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_advanced_security_enabled.cognito_user_pool_advanced_security_enabled import (
|
||||
cognito_user_pool_advanced_security_enabled,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_advanced_security_enabled()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "PASS"
|
||||
assert result[0].status_extended == (
|
||||
f"User pool {user_pool_name} has advanced security enforced with full-function mode."
|
||||
)
|
||||
|
||||
assert result[0].resource_id == user_pool_id
|
||||
assert result[0].resource_arn == user_pool_arn
|
||||
+210
@@ -0,0 +1,210 @@
|
||||
from datetime import datetime
|
||||
from unittest import mock
|
||||
|
||||
from prowler.providers.aws.services.cognito.cognito_service import (
|
||||
CompromisedCredentialsRiskConfiguration,
|
||||
RiskConfiguration,
|
||||
UserPool,
|
||||
)
|
||||
from tests.providers.aws.utils import AWS_ACCOUNT_NUMBER, AWS_REGION_US_EAST_1
|
||||
|
||||
|
||||
class Test_cognito_user_pool_blocks_compromised_credentials_sign_in_attempts:
|
||||
def test_cognito_no_user_pools(self):
|
||||
cognito_client = mock.MagicMock
|
||||
cognito_client.user_pools = {}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_blocks_compromised_credentials_sign_in_attempts.cognito_user_pool_blocks_compromised_credentials_sign_in_attempts import (
|
||||
cognito_user_pool_blocks_compromised_credentials_sign_in_attempts,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_blocks_compromised_credentials_sign_in_attempts()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 0
|
||||
|
||||
def test_cognito_user_pools_advanced_security_off(self):
|
||||
cognito_client = mock.MagicMock
|
||||
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
|
||||
user_pool_name = "user_pool_name"
|
||||
user_pool_id = "eu-west-1_123456789"
|
||||
cognito_client.user_pools = {
|
||||
user_pool_arn: UserPool(
|
||||
advanced_security_mode="OFF",
|
||||
risk_configuration=RiskConfiguration(
|
||||
compromised_credentials_risk_configuration=CompromisedCredentialsRiskConfiguration(
|
||||
event_filter=["SIGN_IN"],
|
||||
actions="BLOCK",
|
||||
)
|
||||
),
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=user_pool_id,
|
||||
arn=user_pool_arn,
|
||||
name=user_pool_name,
|
||||
last_modified=datetime.now(),
|
||||
creation_date=datetime.now(),
|
||||
status="ACTIVE",
|
||||
)
|
||||
}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_blocks_compromised_credentials_sign_in_attempts.cognito_user_pool_blocks_compromised_credentials_sign_in_attempts import (
|
||||
cognito_user_pool_blocks_compromised_credentials_sign_in_attempts,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_blocks_compromised_credentials_sign_in_attempts()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "FAIL"
|
||||
assert result[0].status_extended == (
|
||||
f"User pool {user_pool_name} does not block sign-in attempts with suspected compromised credentials."
|
||||
)
|
||||
assert result[0].resource_id == user_pool_id
|
||||
assert result[0].resource_arn == user_pool_arn
|
||||
|
||||
def test_cognito_user_pools_advanced_security_audit(self):
|
||||
cognito_client = mock.MagicMock
|
||||
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
|
||||
user_pool_name = "user_pool_name"
|
||||
user_pool_id = "eu-west-1_123456789"
|
||||
cognito_client.user_pools = {
|
||||
user_pool_arn: UserPool(
|
||||
advanced_security_mode="AUDIT",
|
||||
risk_configuration=RiskConfiguration(
|
||||
compromised_credentials_risk_configuration=CompromisedCredentialsRiskConfiguration(
|
||||
event_filter=["SIGN_IN"],
|
||||
actions="BLOCK",
|
||||
)
|
||||
),
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=user_pool_id,
|
||||
arn=user_pool_arn,
|
||||
name=user_pool_name,
|
||||
last_modified=datetime.now(),
|
||||
creation_date=datetime.now(),
|
||||
status="ACTIVE",
|
||||
)
|
||||
}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_blocks_compromised_credentials_sign_in_attempts.cognito_user_pool_blocks_compromised_credentials_sign_in_attempts import (
|
||||
cognito_user_pool_blocks_compromised_credentials_sign_in_attempts,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_blocks_compromised_credentials_sign_in_attempts()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "FAIL"
|
||||
assert result[0].status_extended == (
|
||||
f"User pool {user_pool_name} does not block sign-in attempts with suspected compromised credentials."
|
||||
)
|
||||
assert result[0].resource_id == user_pool_id
|
||||
assert result[0].resource_arn == user_pool_arn
|
||||
|
||||
def test_cognito_user_pools_advanced_security_enforced(self):
|
||||
cognito_client = mock.MagicMock
|
||||
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
|
||||
user_pool_name = "user_pool_name"
|
||||
user_pool_id = "eu-west-1_123456789"
|
||||
cognito_client.user_pools = {
|
||||
user_pool_arn: UserPool(
|
||||
advanced_security_mode="ENFORCED",
|
||||
risk_configuration=RiskConfiguration(
|
||||
compromised_credentials_risk_configuration=CompromisedCredentialsRiskConfiguration(
|
||||
event_filter=["SIGN_IN"],
|
||||
actions="BLOCK",
|
||||
)
|
||||
),
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=user_pool_id,
|
||||
arn=user_pool_arn,
|
||||
name=user_pool_name,
|
||||
last_modified=datetime.now(),
|
||||
creation_date=datetime.now(),
|
||||
status="ACTIVE",
|
||||
)
|
||||
}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_blocks_compromised_credentials_sign_in_attempts.cognito_user_pool_blocks_compromised_credentials_sign_in_attempts import (
|
||||
cognito_user_pool_blocks_compromised_credentials_sign_in_attempts,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_blocks_compromised_credentials_sign_in_attempts()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "PASS"
|
||||
assert result[0].status_extended == (
|
||||
f"User pool {user_pool_name} blocks sign-in attempts with suspected compromised credentials."
|
||||
)
|
||||
assert result[0].resource_id == user_pool_id
|
||||
assert result[0].resource_arn == user_pool_arn
|
||||
|
||||
def test_cognito_user_pools_advanced_security_enforced_no_sign_in(self):
|
||||
cognito_client = mock.MagicMock
|
||||
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
|
||||
user_pool_name = "user_pool_name"
|
||||
user_pool_id = "eu-west-1_123456789"
|
||||
cognito_client.user_pools = {
|
||||
user_pool_arn: UserPool(
|
||||
advanced_security_mode="ENFORCED",
|
||||
risk_configuration=RiskConfiguration(
|
||||
compromised_credentials_risk_configuration=CompromisedCredentialsRiskConfiguration(
|
||||
event_filter=[],
|
||||
actions="BLOCK",
|
||||
)
|
||||
),
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=user_pool_id,
|
||||
arn=user_pool_arn,
|
||||
name=user_pool_name,
|
||||
last_modified=datetime.now(),
|
||||
creation_date=datetime.now(),
|
||||
status="ACTIVE",
|
||||
)
|
||||
}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_blocks_compromised_credentials_sign_in_attempts.cognito_user_pool_blocks_compromised_credentials_sign_in_attempts import (
|
||||
cognito_user_pool_blocks_compromised_credentials_sign_in_attempts,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_blocks_compromised_credentials_sign_in_attempts()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "FAIL"
|
||||
assert result[0].status_extended == (
|
||||
f"User pool {user_pool_name} does not block sign-in attempts with suspected compromised credentials."
|
||||
)
|
||||
assert result[0].resource_id == user_pool_id
|
||||
assert result[0].resource_arn == user_pool_arn
|
||||
+215
@@ -0,0 +1,215 @@
|
||||
from datetime import datetime
|
||||
from unittest import mock
|
||||
|
||||
from prowler.providers.aws.services.cognito.cognito_service import (
|
||||
AccountTakeoverRiskConfiguration,
|
||||
RiskConfiguration,
|
||||
UserPool,
|
||||
)
|
||||
from tests.providers.aws.utils import AWS_ACCOUNT_NUMBER, AWS_REGION_US_EAST_1
|
||||
|
||||
|
||||
class Test_cognito_user_pool_blocks_potential_malicious_sign_in_attempts:
|
||||
def test_cognito_no_user_pools(self):
|
||||
cognito_client = mock.MagicMock
|
||||
cognito_client.user_pools = {}
|
||||
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_blocks_potential_malicious_sign_in_attempts.cognito_user_pool_blocks_potential_malicious_sign_in_attempts import (
|
||||
cognito_user_pool_blocks_potential_malicious_sign_in_attempts,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_blocks_potential_malicious_sign_in_attempts()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 0
|
||||
|
||||
def test_cognito_user_pools_advanced_security_off(self):
|
||||
cognito_client = mock.MagicMock
|
||||
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
|
||||
user_pool_name = "user_pool_name"
|
||||
user_pool_id = "eu-west-1_123456789"
|
||||
cognito_client.user_pools = {
|
||||
user_pool_arn: UserPool(
|
||||
advanced_security_mode="OFF",
|
||||
risk_configuration=RiskConfiguration(
|
||||
account_takeover_risk_configuration=AccountTakeoverRiskConfiguration(
|
||||
low_action="BLOCK",
|
||||
medium_action="BLOCK",
|
||||
high_action="BLOCK",
|
||||
)
|
||||
),
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=user_pool_id,
|
||||
arn=user_pool_arn,
|
||||
name=user_pool_name,
|
||||
last_modified=datetime.now(),
|
||||
creation_date=datetime.now(),
|
||||
status="ACTIVE",
|
||||
)
|
||||
}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_blocks_potential_malicious_sign_in_attempts.cognito_user_pool_blocks_potential_malicious_sign_in_attempts import (
|
||||
cognito_user_pool_blocks_potential_malicious_sign_in_attempts,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_blocks_potential_malicious_sign_in_attempts()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "FAIL"
|
||||
assert result[0].status_extended == (
|
||||
f"User pool {user_pool_name} does not block all potential malicious sign-in attempts."
|
||||
)
|
||||
assert result[0].resource_id == user_pool_id
|
||||
assert result[0].resource_arn == user_pool_arn
|
||||
|
||||
def test_cognito_user_pools_advanced_security_audit(self):
|
||||
cognito_client = mock.MagicMock
|
||||
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
|
||||
user_pool_name = "user_pool_name"
|
||||
user_pool_id = "eu-west-1_123456789"
|
||||
cognito_client.user_pools = {
|
||||
user_pool_arn: UserPool(
|
||||
advanced_security_mode="AUDIT",
|
||||
risk_configuration=RiskConfiguration(
|
||||
account_takeover_risk_configuration=AccountTakeoverRiskConfiguration(
|
||||
low_action="BLOCK",
|
||||
medium_action="BLOCK",
|
||||
high_action="BLOCK",
|
||||
)
|
||||
),
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=user_pool_id,
|
||||
arn=user_pool_arn,
|
||||
name=user_pool_name,
|
||||
last_modified=datetime.now(),
|
||||
creation_date=datetime.now(),
|
||||
status="ACTIVE",
|
||||
)
|
||||
}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_blocks_potential_malicious_sign_in_attempts.cognito_user_pool_blocks_potential_malicious_sign_in_attempts import (
|
||||
cognito_user_pool_blocks_potential_malicious_sign_in_attempts,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_blocks_potential_malicious_sign_in_attempts()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "FAIL"
|
||||
assert result[0].status_extended == (
|
||||
f"User pool {user_pool_name} does not block all potential malicious sign-in attempts."
|
||||
)
|
||||
assert result[0].resource_id == user_pool_id
|
||||
assert result[0].resource_arn == user_pool_arn
|
||||
|
||||
def test_cognito_user_pools_advanced_security_enforced(self):
|
||||
cognito_client = mock.MagicMock
|
||||
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
|
||||
user_pool_name = "user_pool_name"
|
||||
user_pool_id = "eu-west-1_123456789"
|
||||
cognito_client.user_pools = {
|
||||
user_pool_arn: UserPool(
|
||||
advanced_security_mode="ENFORCED",
|
||||
risk_configuration=RiskConfiguration(
|
||||
account_takeover_risk_configuration=AccountTakeoverRiskConfiguration(
|
||||
low_action="BLOCK",
|
||||
medium_action="BLOCK",
|
||||
high_action="BLOCK",
|
||||
)
|
||||
),
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=user_pool_id,
|
||||
arn=user_pool_arn,
|
||||
name=user_pool_name,
|
||||
last_modified=datetime.now(),
|
||||
creation_date=datetime.now(),
|
||||
status="ACTIVE",
|
||||
)
|
||||
}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_blocks_potential_malicious_sign_in_attempts.cognito_user_pool_blocks_potential_malicious_sign_in_attempts import (
|
||||
cognito_user_pool_blocks_potential_malicious_sign_in_attempts,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_blocks_potential_malicious_sign_in_attempts()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "PASS"
|
||||
assert result[0].status_extended == (
|
||||
f"User pool {user_pool_name} blocks all potential malicious sign-in attempts."
|
||||
)
|
||||
assert result[0].resource_id == user_pool_id
|
||||
assert result[0].resource_arn == user_pool_arn
|
||||
|
||||
def test_cognito_user_pools_advanced_security_enforced_no_low_action(self):
|
||||
cognito_client = mock.MagicMock
|
||||
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
|
||||
user_pool_name = "user_pool_name"
|
||||
user_pool_id = "eu-west-1_123456789"
|
||||
cognito_client.user_pools = {
|
||||
user_pool_arn: UserPool(
|
||||
advanced_security_mode="ENFORCED",
|
||||
risk_configuration=RiskConfiguration(
|
||||
account_takeover_risk_configuration=AccountTakeoverRiskConfiguration(
|
||||
medium_action="BLOCK",
|
||||
high_action="BLOCK",
|
||||
)
|
||||
),
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=user_pool_id,
|
||||
arn=user_pool_arn,
|
||||
name=user_pool_name,
|
||||
last_modified=datetime.now(),
|
||||
creation_date=datetime.now(),
|
||||
status="ACTIVE",
|
||||
)
|
||||
}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_blocks_potential_malicious_sign_in_attempts.cognito_user_pool_blocks_potential_malicious_sign_in_attempts import (
|
||||
cognito_user_pool_blocks_potential_malicious_sign_in_attempts,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_blocks_potential_malicious_sign_in_attempts()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "FAIL"
|
||||
assert result[0].status_extended == (
|
||||
f"User pool {user_pool_name} does not block all potential malicious sign-in attempts."
|
||||
)
|
||||
|
||||
assert result[0].resource_id == user_pool_id
|
||||
assert result[0].resource_arn == user_pool_arn
|
||||
+130
@@ -0,0 +1,130 @@
|
||||
from datetime import datetime
|
||||
from unittest import mock
|
||||
|
||||
from prowler.providers.aws.services.cognito.cognito_service import (
|
||||
UserPool,
|
||||
UserPoolClient,
|
||||
)
|
||||
from tests.providers.aws.utils import AWS_ACCOUNT_NUMBER, AWS_REGION_US_EAST_1
|
||||
|
||||
|
||||
class Test_cognito_user_pool_client_prevent_user_existence_errors:
|
||||
def test_cognito_no_user_pools(self):
|
||||
cognito_client = mock.MagicMock
|
||||
cognito_client.user_pools = {}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_client_prevent_user_existence_errors.cognito_user_pool_client_prevent_user_existence_errors import (
|
||||
cognito_user_pool_client_prevent_user_existence_errors,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_client_prevent_user_existence_errors()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 0
|
||||
|
||||
def test_cognito_user_pools_prevent_user_existence_errors_disabled(self):
|
||||
cognito_client = mock.MagicMock
|
||||
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
|
||||
user_pool_client_arn = f"{user_pool_arn}/client/eu-west-1_123456789"
|
||||
user_pool_id = "eu-west-1_123456789"
|
||||
user_pool_name = "eu-west-1_123456789"
|
||||
user_pool_client_id = "eu-west-1_123456789"
|
||||
user_pool_client_name = "eu-west-1_123456789"
|
||||
cognito_client.user_pools = {
|
||||
user_pool_arn: UserPool(
|
||||
user_pool_clients={
|
||||
user_pool_client_id: UserPoolClient(
|
||||
id=user_pool_client_id,
|
||||
name=user_pool_client_name,
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
arn=user_pool_client_arn,
|
||||
prevent_user_existence_errors="DISABLED",
|
||||
)
|
||||
},
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=user_pool_id,
|
||||
arn=user_pool_arn,
|
||||
name=user_pool_name,
|
||||
last_modified=datetime.now(),
|
||||
creation_date=datetime.now(),
|
||||
status="ACTIVE",
|
||||
)
|
||||
}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_client_prevent_user_existence_errors.cognito_user_pool_client_prevent_user_existence_errors import (
|
||||
cognito_user_pool_client_prevent_user_existence_errors,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_client_prevent_user_existence_errors()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].resource_id == user_pool_client_id
|
||||
assert result[0].resource_arn == user_pool_client_arn
|
||||
assert result[0].status == "FAIL"
|
||||
assert result[0].status_extended == (
|
||||
f"User pool client {user_pool_client_name} does not prevent revealing users in existence errors."
|
||||
)
|
||||
|
||||
def test_cognito_user_pools_prevent_user_existence_errors_enabled(self):
|
||||
cognito_client = mock.MagicMock
|
||||
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
|
||||
user_pool_client_arn = f"{user_pool_arn}/client/eu-west-1_123456789"
|
||||
user_pool_id = "eu-west-1_123456789"
|
||||
user_pool_name = "user_pool_name"
|
||||
user_pool_client_id = "eu-west-1_123456789"
|
||||
user_pool_client_name = "user_pool_name"
|
||||
cognito_client.user_pools = {
|
||||
user_pool_arn: UserPool(
|
||||
user_pool_clients={
|
||||
user_pool_client_id: UserPoolClient(
|
||||
id=user_pool_client_id,
|
||||
name=user_pool_client_name,
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
arn=user_pool_client_arn,
|
||||
prevent_user_existence_errors="ENABLED",
|
||||
)
|
||||
},
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=user_pool_id,
|
||||
arn=user_pool_arn,
|
||||
name=user_pool_name,
|
||||
last_modified=datetime.now(),
|
||||
creation_date=datetime.now(),
|
||||
status="ACTIVE",
|
||||
)
|
||||
}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_client_prevent_user_existence_errors.cognito_user_pool_client_prevent_user_existence_errors import (
|
||||
cognito_user_pool_client_prevent_user_existence_errors,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_client_prevent_user_existence_errors()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "PASS"
|
||||
assert result[0].status_extended == (
|
||||
f"User pool client {user_pool_client_name} prevents revealing users in existence errors."
|
||||
)
|
||||
|
||||
assert result[0].resource_id == user_pool_client_id
|
||||
assert result[0].resource_arn == user_pool_client_arn
|
||||
+131
@@ -0,0 +1,131 @@
|
||||
from datetime import datetime
|
||||
from unittest import mock
|
||||
|
||||
from prowler.providers.aws.services.cognito.cognito_service import (
|
||||
UserPool,
|
||||
UserPoolClient,
|
||||
)
|
||||
from tests.providers.aws.utils import AWS_ACCOUNT_NUMBER, AWS_REGION_US_EAST_1
|
||||
|
||||
|
||||
class Test_cognito_user_pool_client_token_revocation_enabled:
|
||||
def test_cognito_no_user_pools(self):
|
||||
cognito_client = mock.MagicMock
|
||||
cognito_client.user_pools = {}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_client_token_revocation_enabled.cognito_user_pool_client_token_revocation_enabled import (
|
||||
cognito_user_pool_client_token_revocation_enabled,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_client_token_revocation_enabled()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 0
|
||||
|
||||
def test_cognito_user_pools_token_revocation_disabled(self):
|
||||
cognito_client = mock.MagicMock
|
||||
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
|
||||
user_pool_name = "user_pool_name"
|
||||
user_pool_id = "eu-west-1_123456789"
|
||||
user_pool_client_id = "eu-west-1_123456789"
|
||||
user_pool_client_name = "eu-west-1_123456789"
|
||||
user_pool_client_arn = f"{user_pool_arn}/client/{user_pool_client_id}"
|
||||
cognito_client.user_pools = {
|
||||
user_pool_arn: UserPool(
|
||||
user_pool_clients={
|
||||
user_pool_client_id: UserPoolClient(
|
||||
id=user_pool_client_id,
|
||||
name=user_pool_client_name,
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
arn=user_pool_client_arn,
|
||||
enable_token_revocation=False,
|
||||
)
|
||||
},
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=user_pool_id,
|
||||
arn=user_pool_arn,
|
||||
name=user_pool_name,
|
||||
last_modified=datetime.now(),
|
||||
creation_date=datetime.now(),
|
||||
status="ACTIVE",
|
||||
)
|
||||
}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_client_token_revocation_enabled.cognito_user_pool_client_token_revocation_enabled import (
|
||||
cognito_user_pool_client_token_revocation_enabled,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_client_token_revocation_enabled()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "FAIL"
|
||||
assert result[0].status_extended == (
|
||||
f"User pool client {user_pool_client_name} has token revocation disabled."
|
||||
)
|
||||
|
||||
assert result[0].resource_id == user_pool_client_id
|
||||
assert result[0].resource_arn == user_pool_client_arn
|
||||
|
||||
def test_project_user_pools_token_revocation_enabled(self):
|
||||
cognito_client = mock.MagicMock
|
||||
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
|
||||
user_pool_name = "user_pool_name"
|
||||
user_pool_id = "eu-west-1_123456789"
|
||||
user_pool_client_id = "eu-west-1_123456789"
|
||||
user_pool_client_name = "eu-west-1_123456789"
|
||||
user_pool_client_arn = f"{user_pool_arn}/client/{user_pool_client_id}"
|
||||
cognito_client.user_pools = {
|
||||
user_pool_arn: UserPool(
|
||||
user_pool_clients={
|
||||
user_pool_client_id: UserPoolClient(
|
||||
id=user_pool_client_id,
|
||||
name=user_pool_client_name,
|
||||
arn=user_pool_client_arn,
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
enable_token_revocation=True,
|
||||
)
|
||||
},
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=user_pool_id,
|
||||
arn=user_pool_arn,
|
||||
name=user_pool_name,
|
||||
last_modified=datetime.now(),
|
||||
creation_date=datetime.now(),
|
||||
status="ACTIVE",
|
||||
)
|
||||
}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_client_token_revocation_enabled.cognito_user_pool_client_token_revocation_enabled import (
|
||||
cognito_user_pool_client_token_revocation_enabled,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_client_token_revocation_enabled()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "PASS"
|
||||
assert result[0].status_extended == (
|
||||
f"User pool client {user_pool_client_name} has token revocation enabled."
|
||||
)
|
||||
|
||||
assert result[0].resource_id == user_pool_client_id
|
||||
assert result[0].resource_arn == user_pool_client_arn
|
||||
+105
@@ -0,0 +1,105 @@
|
||||
from datetime import datetime
|
||||
from unittest import mock
|
||||
|
||||
from prowler.providers.aws.services.cognito.cognito_service import UserPool
|
||||
from tests.providers.aws.utils import AWS_ACCOUNT_NUMBER, AWS_REGION_US_EAST_1
|
||||
|
||||
|
||||
class Test_cognito_user_pool_deletion_protection_enabled:
|
||||
def test_cognito_no_user_pools(self):
|
||||
cognito_client = mock.MagicMock
|
||||
cognito_client.user_pools = {}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_deletion_protection_enabled.cognito_user_pool_deletion_protection_enabled import (
|
||||
cognito_user_pool_deletion_protection_enabled,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_deletion_protection_enabled()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 0
|
||||
|
||||
def test_cognito_user_pools_deletion_protection_disabled(self):
|
||||
cognito_client = mock.MagicMock
|
||||
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
|
||||
user_pool_name = "user_pool_name"
|
||||
user_pool_id = "eu-west-1_123456789"
|
||||
cognito_client.user_pools = {
|
||||
user_pool_arn: UserPool(
|
||||
deletion_protection="DISABLED",
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=user_pool_id,
|
||||
arn=user_pool_arn,
|
||||
name=user_pool_name,
|
||||
last_modified=datetime.now(),
|
||||
creation_date=datetime.now(),
|
||||
status="ACTIVE",
|
||||
)
|
||||
}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_deletion_protection_enabled.cognito_user_pool_deletion_protection_enabled import (
|
||||
cognito_user_pool_deletion_protection_enabled,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_deletion_protection_enabled()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "FAIL"
|
||||
assert result[0].status_extended == (
|
||||
f"User pool {user_pool_name} has deletion protection disabled."
|
||||
)
|
||||
assert result[0].resource_id == user_pool_id
|
||||
assert result[0].resource_arn == user_pool_arn
|
||||
|
||||
def test_cognito_user_pools_deletion_protection_enabled(self):
|
||||
cognito_client = mock.MagicMock
|
||||
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
|
||||
user_pool_name = "user_pool_name"
|
||||
user_pool_id = "eu-west-1_123456789"
|
||||
cognito_client.user_pools = {
|
||||
user_pool_arn: UserPool(
|
||||
deletion_protection="ACTIVE",
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=user_pool_id,
|
||||
arn=user_pool_arn,
|
||||
name=user_pool_name,
|
||||
last_modified=datetime.now(),
|
||||
creation_date=datetime.now(),
|
||||
status="ACTIVE",
|
||||
)
|
||||
}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_deletion_protection_enabled.cognito_user_pool_deletion_protection_enabled import (
|
||||
cognito_user_pool_deletion_protection_enabled,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_deletion_protection_enabled()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "PASS"
|
||||
assert result[0].status_extended == (
|
||||
f"User pool {user_pool_name} has deletion protection enabled."
|
||||
)
|
||||
|
||||
assert result[0].resource_id == user_pool_id
|
||||
assert result[0].resource_arn == user_pool_arn
|
||||
+146
@@ -0,0 +1,146 @@
|
||||
from datetime import datetime
|
||||
from unittest import mock
|
||||
|
||||
from prowler.providers.aws.services.cognito.cognito_service import UserPool
|
||||
from tests.providers.aws.utils import AWS_ACCOUNT_NUMBER, AWS_REGION_US_EAST_1
|
||||
|
||||
|
||||
class Test_cognito_user_pool_mfa_enabled:
|
||||
def test_cognito_no_user_pools(self):
|
||||
cognito_client = mock.MagicMock
|
||||
cognito_client.user_pools = {}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_mfa_enabled.cognito_user_pool_mfa_enabled import (
|
||||
cognito_user_pool_mfa_enabled,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_mfa_enabled()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 0
|
||||
|
||||
def test_cognito_user_pools_mfa_config_none(self):
|
||||
cognito_client = mock.MagicMock
|
||||
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
|
||||
user_pool_id = "eu-west-1_123456789"
|
||||
user_pool_name = "user_pool_name"
|
||||
cognito_client.user_pools = {
|
||||
user_pool_arn: UserPool(
|
||||
mfa_config=None,
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=user_pool_id,
|
||||
arn=user_pool_arn,
|
||||
name=user_pool_name,
|
||||
last_modified=datetime.now(),
|
||||
creation_date=datetime.now(),
|
||||
status="ACTIVE",
|
||||
)
|
||||
}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_mfa_enabled.cognito_user_pool_mfa_enabled import (
|
||||
cognito_user_pool_mfa_enabled,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_mfa_enabled()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "FAIL"
|
||||
assert result[0].status_extended == (
|
||||
f"User pool {user_pool_name} has MFA disabled."
|
||||
)
|
||||
|
||||
assert result[0].resource_id == user_pool_id
|
||||
assert result[0].resource_arn == user_pool_arn
|
||||
|
||||
def test_cognito_user_pools_mfa_config_disabled(self):
|
||||
cognito_client = mock.MagicMock
|
||||
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
|
||||
user_pool_id = "eu-west-1_123456789"
|
||||
user_pool_name = "user_pool_name"
|
||||
cognito_client.user_pools = {
|
||||
user_pool_arn: UserPool(
|
||||
mfa_config={"status": "OFF"},
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=user_pool_id,
|
||||
arn=user_pool_arn,
|
||||
name=user_pool_name,
|
||||
last_modified=datetime.now(),
|
||||
creation_date=datetime.now(),
|
||||
status="ACTIVE",
|
||||
)
|
||||
}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_mfa_enabled.cognito_user_pool_mfa_enabled import (
|
||||
cognito_user_pool_mfa_enabled,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_mfa_enabled()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "FAIL"
|
||||
assert result[0].status_extended == (
|
||||
f"User pool {user_pool_name} has MFA disabled."
|
||||
)
|
||||
|
||||
assert result[0].resource_id == user_pool_id
|
||||
assert result[0].resource_arn == user_pool_arn
|
||||
|
||||
def test_cognito_user_pools_mfa_config_enabled(self):
|
||||
cognito_client = mock.MagicMock
|
||||
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
|
||||
user_pool_id = "eu-west-1_123456789"
|
||||
user_pool_name = "user_pool_name"
|
||||
cognito_client.user_pools = {
|
||||
user_pool_arn: UserPool(
|
||||
mfa_config={"status": "ON"},
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=user_pool_id,
|
||||
arn=user_pool_arn,
|
||||
name=user_pool_name,
|
||||
last_modified=datetime.now(),
|
||||
creation_date=datetime.now(),
|
||||
status="ACTIVE",
|
||||
)
|
||||
}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_mfa_enabled.cognito_user_pool_mfa_enabled import (
|
||||
cognito_user_pool_mfa_enabled,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_mfa_enabled()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "PASS"
|
||||
assert result[0].status_extended == (
|
||||
f"User pool {user_pool_name} has MFA enabled."
|
||||
)
|
||||
|
||||
assert result[0].resource_id == user_pool_id
|
||||
assert result[0].resource_arn == user_pool_arn
|
||||
+153
@@ -0,0 +1,153 @@
|
||||
from datetime import datetime
|
||||
from unittest import mock
|
||||
|
||||
from prowler.providers.aws.services.cognito.cognito_service import (
|
||||
PasswordPolicy,
|
||||
UserPool,
|
||||
)
|
||||
from tests.providers.aws.utils import AWS_ACCOUNT_NUMBER, AWS_REGION_US_EAST_1
|
||||
|
||||
|
||||
class Test_cognito_user_pool_password_policy_lowercase:
|
||||
def test_cognito_no_user_pools(self):
|
||||
cognito_client = mock.MagicMock
|
||||
cognito_client.user_pools = {}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_password_policy_lowercase.cognito_user_pool_password_policy_lowercase import (
|
||||
cognito_user_pool_password_policy_lowercase,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_password_policy_lowercase()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 0
|
||||
|
||||
def test_cognito_user_pools_bad_password_policy(self):
|
||||
cognito_client = mock.MagicMock
|
||||
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
|
||||
user_pool_id = "eu-west-1_123456789"
|
||||
user_pool_name = "user_pool_name"
|
||||
cognito_client.user_pools = {
|
||||
user_pool_arn: UserPool(
|
||||
password_policy=PasswordPolicy(
|
||||
require_lowercase=False,
|
||||
),
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=user_pool_id,
|
||||
arn=user_pool_arn,
|
||||
name=user_pool_name,
|
||||
last_modified=datetime.now(),
|
||||
creation_date=datetime.now(),
|
||||
status="ACTIVE",
|
||||
)
|
||||
}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_password_policy_lowercase.cognito_user_pool_password_policy_lowercase import (
|
||||
cognito_user_pool_password_policy_lowercase,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_password_policy_lowercase()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "FAIL"
|
||||
assert result[0].status_extended == (
|
||||
f"User pool {user_pool_name} does not have a password policy with a lowercase requirement."
|
||||
)
|
||||
|
||||
assert result[0].resource_id == user_pool_id
|
||||
assert result[0].resource_arn == user_pool_arn
|
||||
|
||||
def test_cognito_user_pools_good_password_policy(self):
|
||||
cognito_client = mock.MagicMock
|
||||
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
|
||||
user_pool_id = "eu-west-1_123456789"
|
||||
user_pool_name = "user_pool_name"
|
||||
cognito_client.user_pools = {
|
||||
user_pool_arn: UserPool(
|
||||
password_policy=PasswordPolicy(
|
||||
require_lowercase=True,
|
||||
),
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=user_pool_id,
|
||||
arn=user_pool_arn,
|
||||
name=user_pool_name,
|
||||
last_modified=datetime.now(),
|
||||
creation_date=datetime.now(),
|
||||
status="ACTIVE",
|
||||
)
|
||||
}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_password_policy_lowercase.cognito_user_pool_password_policy_lowercase import (
|
||||
cognito_user_pool_password_policy_lowercase,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_password_policy_lowercase()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "PASS"
|
||||
assert result[0].status_extended == (
|
||||
f"User pool {user_pool_name} has a password policy with a lowercase requirement."
|
||||
)
|
||||
|
||||
assert result[0].resource_id == user_pool_id
|
||||
assert result[0].resource_arn == user_pool_arn
|
||||
|
||||
def test_cognito_user_pools_no_password_policy(self):
|
||||
cognito_client = mock.MagicMock
|
||||
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
|
||||
user_pool_id = "eu-west-1_123456789"
|
||||
user_pool_name = "user_pool_name"
|
||||
cognito_client.user_pools = {
|
||||
user_pool_arn: UserPool(
|
||||
password_policy=None,
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=user_pool_id,
|
||||
arn=user_pool_arn,
|
||||
name=user_pool_name,
|
||||
last_modified=datetime.now(),
|
||||
creation_date=datetime.now(),
|
||||
status="ACTIVE",
|
||||
)
|
||||
}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_password_policy_lowercase.cognito_user_pool_password_policy_lowercase import (
|
||||
cognito_user_pool_password_policy_lowercase,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_password_policy_lowercase()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "FAIL"
|
||||
assert result[0].status_extended == (
|
||||
f"User pool {user_pool_name} has not a password policy set."
|
||||
)
|
||||
|
||||
assert result[0].resource_id == user_pool_id
|
||||
assert result[0].resource_arn == user_pool_arn
|
||||
+153
@@ -0,0 +1,153 @@
|
||||
from datetime import datetime
|
||||
from unittest import mock
|
||||
|
||||
from prowler.providers.aws.services.cognito.cognito_service import (
|
||||
PasswordPolicy,
|
||||
UserPool,
|
||||
)
|
||||
from tests.providers.aws.utils import AWS_ACCOUNT_NUMBER, AWS_REGION_US_EAST_1
|
||||
|
||||
|
||||
class Test_cognito_user_pool_password_policy_minimum_length_14:
|
||||
def test_cognito_no_user_pools(self):
|
||||
cognito_client = mock.MagicMock
|
||||
cognito_client.user_pools = {}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_password_policy_minimum_length_14.cognito_user_pool_password_policy_minimum_length_14 import (
|
||||
cognito_user_pool_password_policy_minimum_length_14,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_password_policy_minimum_length_14()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 0
|
||||
|
||||
def test_cognito_user_pools_bad_password_policy(self):
|
||||
cognito_client = mock.MagicMock
|
||||
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
|
||||
user_pool_id = "eu-west-1_123456789"
|
||||
user_pool_name = "user_pool_name"
|
||||
cognito_client.user_pools = {
|
||||
user_pool_arn: UserPool(
|
||||
password_policy=PasswordPolicy(
|
||||
minimum_length=10,
|
||||
),
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=user_pool_id,
|
||||
arn=user_pool_arn,
|
||||
name=user_pool_name,
|
||||
last_modified=datetime.now(),
|
||||
creation_date=datetime.now(),
|
||||
status="ACTIVE",
|
||||
)
|
||||
}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_password_policy_minimum_length_14.cognito_user_pool_password_policy_minimum_length_14 import (
|
||||
cognito_user_pool_password_policy_minimum_length_14,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_password_policy_minimum_length_14()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "FAIL"
|
||||
assert result[0].status_extended == (
|
||||
f"User pool {user_pool_name} does not have a password policy with a minimum length of 14 characters."
|
||||
)
|
||||
|
||||
assert result[0].resource_id == user_pool_id
|
||||
assert result[0].resource_arn == user_pool_arn
|
||||
|
||||
def test_cognito_user_pools_good_password_policy(self):
|
||||
cognito_client = mock.MagicMock
|
||||
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
|
||||
user_pool_id = "eu-west-1_123456789"
|
||||
user_pool_name = "user_pool_name"
|
||||
cognito_client.user_pools = {
|
||||
user_pool_arn: UserPool(
|
||||
password_policy=PasswordPolicy(
|
||||
minimum_length=14,
|
||||
),
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=user_pool_id,
|
||||
arn=user_pool_arn,
|
||||
name=user_pool_name,
|
||||
last_modified=datetime.now(),
|
||||
creation_date=datetime.now(),
|
||||
status="ACTIVE",
|
||||
)
|
||||
}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_password_policy_minimum_length_14.cognito_user_pool_password_policy_minimum_length_14 import (
|
||||
cognito_user_pool_password_policy_minimum_length_14,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_password_policy_minimum_length_14()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "PASS"
|
||||
assert result[0].status_extended == (
|
||||
f"User pool {user_pool_name} has a password policy with a minimum length of 14 characters."
|
||||
)
|
||||
|
||||
assert result[0].resource_id == user_pool_id
|
||||
assert result[0].resource_arn == user_pool_arn
|
||||
|
||||
def test_cognito_user_pools_no_password_policy(self):
|
||||
cognito_client = mock.MagicMock
|
||||
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
|
||||
user_pool_id = "eu-west-1_123456789"
|
||||
user_pool_name = "user_pool_name"
|
||||
cognito_client.user_pools = {
|
||||
user_pool_arn: UserPool(
|
||||
password_policy=None,
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=user_pool_id,
|
||||
arn=user_pool_arn,
|
||||
name=user_pool_name,
|
||||
last_modified=datetime.now(),
|
||||
creation_date=datetime.now(),
|
||||
status="ACTIVE",
|
||||
)
|
||||
}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_password_policy_minimum_length_14.cognito_user_pool_password_policy_minimum_length_14 import (
|
||||
cognito_user_pool_password_policy_minimum_length_14,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_password_policy_minimum_length_14()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "FAIL"
|
||||
assert result[0].status_extended == (
|
||||
f"User pool {user_pool_name} has not a password policy set."
|
||||
)
|
||||
|
||||
assert result[0].resource_id == user_pool_id
|
||||
assert result[0].resource_arn == user_pool_arn
|
||||
+153
@@ -0,0 +1,153 @@
|
||||
from datetime import datetime
|
||||
from unittest import mock
|
||||
|
||||
from prowler.providers.aws.services.cognito.cognito_service import (
|
||||
PasswordPolicy,
|
||||
UserPool,
|
||||
)
|
||||
from tests.providers.aws.utils import AWS_ACCOUNT_NUMBER, AWS_REGION_US_EAST_1
|
||||
|
||||
|
||||
class Test_cognito_user_pool_password_policy_number:
|
||||
def test_cognito_no_user_pools(self):
|
||||
cognito_client = mock.MagicMock
|
||||
cognito_client.user_pools = {}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_password_policy_number.cognito_user_pool_password_policy_number import (
|
||||
cognito_user_pool_password_policy_number,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_password_policy_number()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 0
|
||||
|
||||
def test_cognito_user_pools_bad_password_policy(self):
|
||||
cognito_client = mock.MagicMock
|
||||
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
|
||||
user_pool_id = "eu-west-1_123456789"
|
||||
user_pool_name = "user_pool_name"
|
||||
cognito_client.user_pools = {
|
||||
user_pool_arn: UserPool(
|
||||
password_policy={
|
||||
"RequireNumbers": False,
|
||||
},
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=user_pool_id,
|
||||
arn=user_pool_arn,
|
||||
name=user_pool_name,
|
||||
last_modified=datetime.now(),
|
||||
creation_date=datetime.now(),
|
||||
status="ACTIVE",
|
||||
)
|
||||
}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_password_policy_number.cognito_user_pool_password_policy_number import (
|
||||
cognito_user_pool_password_policy_number,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_password_policy_number()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "FAIL"
|
||||
assert result[0].status_extended == (
|
||||
f"User pool {user_pool_name} does not have a password policy with a number requirement."
|
||||
)
|
||||
|
||||
assert result[0].resource_id == user_pool_id
|
||||
assert result[0].resource_arn == user_pool_arn
|
||||
|
||||
def test_cognito_user_pools_good_password_policy(self):
|
||||
cognito_client = mock.MagicMock
|
||||
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
|
||||
user_pool_id = "eu-west-1_123456789"
|
||||
user_pool_name = "user_pool_name"
|
||||
cognito_client.user_pools = {
|
||||
user_pool_arn: UserPool(
|
||||
password_policy=PasswordPolicy(
|
||||
require_numbers=True,
|
||||
),
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=user_pool_id,
|
||||
arn=user_pool_arn,
|
||||
name=user_pool_name,
|
||||
last_modified=datetime.now(),
|
||||
creation_date=datetime.now(),
|
||||
status="ACTIVE",
|
||||
)
|
||||
}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_password_policy_number.cognito_user_pool_password_policy_number import (
|
||||
cognito_user_pool_password_policy_number,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_password_policy_number()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "PASS"
|
||||
assert result[0].status_extended == (
|
||||
f"User pool {user_pool_name} has a password policy with a number requirement."
|
||||
)
|
||||
|
||||
assert result[0].resource_id == user_pool_id
|
||||
assert result[0].resource_arn == user_pool_arn
|
||||
|
||||
def test_cognito_user_pools_no_password_policy(self):
|
||||
cognito_client = mock.MagicMock
|
||||
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
|
||||
user_pool_id = "eu-west-1_123456789"
|
||||
user_pool_name = "user_pool_name"
|
||||
cognito_client.user_pools = {
|
||||
user_pool_arn: UserPool(
|
||||
password_policy=None,
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=user_pool_id,
|
||||
arn=user_pool_arn,
|
||||
name=user_pool_name,
|
||||
last_modified=datetime.now(),
|
||||
creation_date=datetime.now(),
|
||||
status="ACTIVE",
|
||||
)
|
||||
}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_password_policy_number.cognito_user_pool_password_policy_number import (
|
||||
cognito_user_pool_password_policy_number,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_password_policy_number()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "FAIL"
|
||||
assert result[0].status_extended == (
|
||||
f"User pool {user_pool_name} has not a password policy set."
|
||||
)
|
||||
|
||||
assert result[0].resource_id == user_pool_id
|
||||
assert result[0].resource_arn == user_pool_arn
|
||||
+153
@@ -0,0 +1,153 @@
|
||||
from datetime import datetime
|
||||
from unittest import mock
|
||||
|
||||
from prowler.providers.aws.services.cognito.cognito_service import (
|
||||
PasswordPolicy,
|
||||
UserPool,
|
||||
)
|
||||
from tests.providers.aws.utils import AWS_ACCOUNT_NUMBER, AWS_REGION_US_EAST_1
|
||||
|
||||
|
||||
class Test_cognito_user_pool_password_policy_symbol:
|
||||
def test_cognito_no_user_pools(self):
|
||||
cognito_client = mock.MagicMock
|
||||
cognito_client.user_pools = {}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_password_policy_symbol.cognito_user_pool_password_policy_symbol import (
|
||||
cognito_user_pool_password_policy_symbol,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_password_policy_symbol()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 0
|
||||
|
||||
def test_cognito_user_pools_bad_password_policy(self):
|
||||
cognito_client = mock.MagicMock
|
||||
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
|
||||
user_pool_id = "eu-west-1_123456789"
|
||||
user_pool_name = "user_pool_name"
|
||||
cognito_client.user_pools = {
|
||||
user_pool_arn: UserPool(
|
||||
password_policy=PasswordPolicy(
|
||||
require_symbols=False,
|
||||
),
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=user_pool_id,
|
||||
arn=user_pool_arn,
|
||||
name=user_pool_name,
|
||||
last_modified=datetime.now(),
|
||||
creation_date=datetime.now(),
|
||||
status="ACTIVE",
|
||||
)
|
||||
}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_password_policy_symbol.cognito_user_pool_password_policy_symbol import (
|
||||
cognito_user_pool_password_policy_symbol,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_password_policy_symbol()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "FAIL"
|
||||
assert result[0].status_extended == (
|
||||
f"User pool {user_pool_name} does not have a password policy with a symbol requirement."
|
||||
)
|
||||
|
||||
assert result[0].resource_id == user_pool_id
|
||||
assert result[0].resource_arn == user_pool_arn
|
||||
|
||||
def test_cognito_user_pools_good_password_policy(self):
|
||||
cognito_client = mock.MagicMock
|
||||
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
|
||||
user_pool_id = "eu-west-1_123456789"
|
||||
user_pool_name = "user_pool_name"
|
||||
cognito_client.user_pools = {
|
||||
user_pool_arn: UserPool(
|
||||
password_policy=PasswordPolicy(
|
||||
require_symbols=True,
|
||||
),
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=user_pool_id,
|
||||
arn=user_pool_arn,
|
||||
name=user_pool_name,
|
||||
last_modified=datetime.now(),
|
||||
creation_date=datetime.now(),
|
||||
status="ACTIVE",
|
||||
)
|
||||
}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_password_policy_symbol.cognito_user_pool_password_policy_symbol import (
|
||||
cognito_user_pool_password_policy_symbol,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_password_policy_symbol()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "PASS"
|
||||
assert result[0].status_extended == (
|
||||
f"User pool {user_pool_name} has a password policy with a symbol requirement."
|
||||
)
|
||||
|
||||
assert result[0].resource_id == user_pool_id
|
||||
assert result[0].resource_arn == user_pool_arn
|
||||
|
||||
def test_cognito_user_pools_no_password_policy(self):
|
||||
cognito_client = mock.MagicMock
|
||||
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
|
||||
user_pool_id = "eu-west-1_123456789"
|
||||
user_pool_name = "user_pool_name"
|
||||
cognito_client.user_pools = {
|
||||
user_pool_arn: UserPool(
|
||||
password_policy=None,
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=user_pool_id,
|
||||
arn=user_pool_arn,
|
||||
name=user_pool_name,
|
||||
last_modified=datetime.now(),
|
||||
creation_date=datetime.now(),
|
||||
status="ACTIVE",
|
||||
)
|
||||
}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_password_policy_symbol.cognito_user_pool_password_policy_symbol import (
|
||||
cognito_user_pool_password_policy_symbol,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_password_policy_symbol()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "FAIL"
|
||||
assert result[0].status_extended == (
|
||||
f"User pool {user_pool_name} has not a password policy set."
|
||||
)
|
||||
|
||||
assert result[0].resource_id == user_pool_id
|
||||
assert result[0].resource_arn == user_pool_arn
|
||||
+153
@@ -0,0 +1,153 @@
|
||||
from datetime import datetime
|
||||
from unittest import mock
|
||||
|
||||
from prowler.providers.aws.services.cognito.cognito_service import (
|
||||
PasswordPolicy,
|
||||
UserPool,
|
||||
)
|
||||
from tests.providers.aws.utils import AWS_ACCOUNT_NUMBER, AWS_REGION_US_EAST_1
|
||||
|
||||
|
||||
class Test_cognito_user_pool_password_policy_uppercase:
|
||||
def test_cognito_no_user_pools(self):
|
||||
cognito_client = mock.MagicMock
|
||||
cognito_client.user_pools = {}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_password_policy_uppercase.cognito_user_pool_password_policy_uppercase import (
|
||||
cognito_user_pool_password_policy_uppercase,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_password_policy_uppercase()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 0
|
||||
|
||||
def test_cognito_user_pools_bad_password_policy(self):
|
||||
cognito_client = mock.MagicMock
|
||||
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
|
||||
user_pool_id = "eu-west-1_123456789"
|
||||
user_pool_name = "user_pool_name"
|
||||
cognito_client.user_pools = {
|
||||
user_pool_arn: UserPool(
|
||||
password_policy=PasswordPolicy(
|
||||
require_uppercase=False,
|
||||
),
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=user_pool_id,
|
||||
arn=user_pool_arn,
|
||||
name=user_pool_name,
|
||||
last_modified=datetime.now(),
|
||||
creation_date=datetime.now(),
|
||||
status="ACTIVE",
|
||||
)
|
||||
}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_password_policy_uppercase.cognito_user_pool_password_policy_uppercase import (
|
||||
cognito_user_pool_password_policy_uppercase,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_password_policy_uppercase()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "FAIL"
|
||||
assert result[0].status_extended == (
|
||||
f"User pool {user_pool_name} does not have a password policy with an uppercase requirement."
|
||||
)
|
||||
|
||||
assert result[0].resource_id == user_pool_id
|
||||
assert result[0].resource_arn == user_pool_arn
|
||||
|
||||
def test_cognito_user_pools_good_password_policy(self):
|
||||
cognito_client = mock.MagicMock
|
||||
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
|
||||
user_pool_id = "eu-west-1_123456789"
|
||||
user_pool_name = "user_pool_name"
|
||||
cognito_client.user_pools = {
|
||||
user_pool_arn: UserPool(
|
||||
password_policy=PasswordPolicy(
|
||||
require_uppercase=True,
|
||||
),
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=user_pool_id,
|
||||
arn=user_pool_arn,
|
||||
name=user_pool_name,
|
||||
last_modified=datetime.now(),
|
||||
creation_date=datetime.now(),
|
||||
status="ACTIVE",
|
||||
)
|
||||
}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_password_policy_uppercase.cognito_user_pool_password_policy_uppercase import (
|
||||
cognito_user_pool_password_policy_uppercase,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_password_policy_uppercase()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "PASS"
|
||||
assert result[0].status_extended == (
|
||||
f"User pool {user_pool_name} has a password policy with an uppercase requirement."
|
||||
)
|
||||
|
||||
assert result[0].resource_id == user_pool_id
|
||||
assert result[0].resource_arn == user_pool_arn
|
||||
|
||||
def test_cognito_user_pools_no_password_policy(self):
|
||||
cognito_client = mock.MagicMock
|
||||
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
|
||||
user_pool_id = "eu-west-1_123456789"
|
||||
user_pool_name = "user_pool_name"
|
||||
cognito_client.user_pools = {
|
||||
user_pool_arn: UserPool(
|
||||
password_policy=None,
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=user_pool_id,
|
||||
arn=user_pool_arn,
|
||||
name=user_pool_name,
|
||||
last_modified=datetime.now(),
|
||||
creation_date=datetime.now(),
|
||||
status="ACTIVE",
|
||||
)
|
||||
}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_password_policy_uppercase.cognito_user_pool_password_policy_uppercase import (
|
||||
cognito_user_pool_password_policy_uppercase,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_password_policy_uppercase()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "FAIL"
|
||||
assert result[0].status_extended == (
|
||||
f"User pool {user_pool_name} has not a password policy set."
|
||||
)
|
||||
|
||||
assert result[0].resource_id == user_pool_id
|
||||
assert result[0].resource_arn == user_pool_arn
|
||||
+227
@@ -0,0 +1,227 @@
|
||||
from datetime import datetime
|
||||
from unittest import mock
|
||||
|
||||
from prowler.providers.aws.services.cognito.cognito_service import (
|
||||
AdminCreateUserConfig,
|
||||
IdentityPool,
|
||||
IdentityPoolRoles,
|
||||
UserPool,
|
||||
)
|
||||
from tests.providers.aws.utils import AWS_ACCOUNT_NUMBER, AWS_REGION_US_EAST_1
|
||||
|
||||
|
||||
class Test_cognito_user_pool_self_registration_disabled:
|
||||
def test_cognito_no_user_pools(self):
|
||||
cognito_client = mock.MagicMock
|
||||
cognito_client.user_pools = {}
|
||||
cognito_identity_client = mock.MagicMock
|
||||
cognito_identity_client.identity_pools = {}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIdentity",
|
||||
cognito_identity_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_identity_client.cognito_identity_client",
|
||||
cognito_identity_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_self_registration_disabled.cognito_user_pool_self_registration_disabled import (
|
||||
cognito_user_pool_self_registration_disabled,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_self_registration_disabled()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 0
|
||||
|
||||
def test_cognito_no_identity_pools(self):
|
||||
cognito_client = mock.MagicMock
|
||||
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
|
||||
user_pool_id = "eu-west-1_123456789"
|
||||
user_pool_name = "eu-west-1_123456789"
|
||||
cognito_client.user_pools = {
|
||||
user_pool_arn: UserPool(
|
||||
admin_create_user_config=AdminCreateUserConfig(
|
||||
allow_admin_create_user_only=False
|
||||
),
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=user_pool_id,
|
||||
arn=user_pool_arn,
|
||||
name=user_pool_name,
|
||||
last_modified=datetime.now(),
|
||||
creation_date=datetime.now(),
|
||||
status="ACTIVE",
|
||||
)
|
||||
}
|
||||
cognito_identity_client = mock.MagicMock
|
||||
cognito_identity_client.identity_pools = {}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIdentity",
|
||||
cognito_identity_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_identity_client.cognito_identity_client",
|
||||
cognito_identity_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_self_registration_disabled.cognito_user_pool_self_registration_disabled import (
|
||||
cognito_user_pool_self_registration_disabled,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_self_registration_disabled()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "FAIL"
|
||||
assert result[0].status_extended == (
|
||||
f"User pool {user_pool_name} has self registration enabled."
|
||||
)
|
||||
|
||||
assert result[0].resource_id == user_pool_id
|
||||
assert result[0].resource_arn == user_pool_arn
|
||||
|
||||
def test_cognito_identity_pools_allow_admin_create_user_enabled(self):
|
||||
cognito_client = mock.MagicMock
|
||||
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
|
||||
user_pool_id = "eu-west-1_123456789"
|
||||
user_pool_name = "eu-west-1_123456789"
|
||||
cognito_client.user_pools = {
|
||||
user_pool_arn: UserPool(
|
||||
admin_create_user_config=AdminCreateUserConfig(
|
||||
allow_admin_create_user_only=True
|
||||
),
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=user_pool_id,
|
||||
arn=user_pool_arn,
|
||||
name=user_pool_name,
|
||||
last_modified=datetime.now(),
|
||||
creation_date=datetime.now(),
|
||||
status="ACTIVE",
|
||||
)
|
||||
}
|
||||
cognito_identity_client = mock.MagicMock
|
||||
identity_pool_name = "identity_pool_name"
|
||||
identity_pool_id = "eu-west-1_123456789"
|
||||
identity_pool_arn = f"arn:aws:cognito-identity:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:identitypool/eu-west-1_123456789"
|
||||
authenticated_role = "authenticated_role"
|
||||
cognito_identity_client.identity_pools = {
|
||||
identity_pool_arn: IdentityPool(
|
||||
id=identity_pool_id,
|
||||
arn=identity_pool_arn,
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
name=identity_pool_name,
|
||||
associated_pools=[
|
||||
{
|
||||
"ProviderName": f"cognito-idp.{AWS_REGION_US_EAST_1}.amazonaws.com/eu-west-1_123456789"
|
||||
}
|
||||
],
|
||||
roles=IdentityPoolRoles(
|
||||
authenticated=authenticated_role,
|
||||
),
|
||||
)
|
||||
}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIdentity",
|
||||
cognito_identity_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_identity_client.cognito_identity_client",
|
||||
cognito_identity_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_self_registration_disabled.cognito_user_pool_self_registration_disabled import (
|
||||
cognito_user_pool_self_registration_disabled,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_self_registration_disabled()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "PASS"
|
||||
assert result[0].status_extended == (
|
||||
f"User pool {user_pool_name} has self registration disabled."
|
||||
)
|
||||
|
||||
assert result[0].resource_id == user_pool_id
|
||||
assert result[0].resource_arn == user_pool_arn
|
||||
|
||||
def test_cognito_identity_pools_allow_admin_create_user_disabled(self):
|
||||
cognito_client = mock.MagicMock
|
||||
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
|
||||
user_pool_name = "eu-west-1_123456789"
|
||||
user_pool_id = "eu-west-1_123456789"
|
||||
cognito_client.user_pools = {
|
||||
user_pool_arn: UserPool(
|
||||
admin_create_user_config=AdminCreateUserConfig(
|
||||
allow_admin_create_user_only=False
|
||||
),
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=user_pool_id,
|
||||
arn=user_pool_arn,
|
||||
name=user_pool_name,
|
||||
last_modified=datetime.now(),
|
||||
creation_date=datetime.now(),
|
||||
status="ACTIVE",
|
||||
)
|
||||
}
|
||||
cognito_identity_client = mock.MagicMock
|
||||
identity_pool_name = "eu-west-1_123456789"
|
||||
identity_pool_id = "eu-west-1_123456789"
|
||||
identity_pool_arn = f"arn:aws:cognito-identity:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:identitypool/eu-west-1_123456789"
|
||||
authenticated_role = "authenticated_role"
|
||||
cognito_identity_client.identity_pools = {
|
||||
identity_pool_arn: IdentityPool(
|
||||
id=identity_pool_id,
|
||||
arn=identity_pool_arn,
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
name=identity_pool_name,
|
||||
associated_pools=[
|
||||
{
|
||||
"ProviderName": f"cognito-idp.{AWS_REGION_US_EAST_1}.amazonaws.com/eu-west-1_123456789"
|
||||
}
|
||||
],
|
||||
roles=IdentityPoolRoles(
|
||||
authenticated=authenticated_role,
|
||||
),
|
||||
)
|
||||
}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIdentity",
|
||||
cognito_identity_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_identity_client.cognito_identity_client",
|
||||
cognito_identity_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_self_registration_disabled.cognito_user_pool_self_registration_disabled import (
|
||||
cognito_user_pool_self_registration_disabled,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_self_registration_disabled()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "FAIL"
|
||||
assert result[0].status_extended == (
|
||||
f"User pool {user_pool_name} has self registration enabled assuming the role(s): {identity_pool_name}({authenticated_role})."
|
||||
)
|
||||
|
||||
assert result[0].resource_id == user_pool_id
|
||||
assert result[0].resource_arn == user_pool_arn
|
||||
+113
@@ -0,0 +1,113 @@
|
||||
from datetime import datetime
|
||||
from unittest import mock
|
||||
|
||||
from prowler.providers.aws.services.cognito.cognito_service import (
|
||||
PasswordPolicy,
|
||||
UserPool,
|
||||
)
|
||||
from tests.providers.aws.utils import AWS_ACCOUNT_NUMBER, AWS_REGION_US_EAST_1
|
||||
|
||||
|
||||
class Test_cognito_user_pool_temporary_password_expiration:
|
||||
def test_cognito_no_user_pools(self):
|
||||
cognito_client = mock.MagicMock
|
||||
cognito_client.user_pools = {}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_temporary_password_expiration.cognito_user_pool_temporary_password_expiration import (
|
||||
cognito_user_pool_temporary_password_expiration,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_temporary_password_expiration()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 0
|
||||
|
||||
def test_cognito_user_pools_password_expiration_8(self):
|
||||
cognito_client = mock.MagicMock
|
||||
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
|
||||
user_pool_id = "eu-west-1_123456789"
|
||||
user_pool_name = "user_pool_name"
|
||||
cognito_client.user_pools = {
|
||||
user_pool_arn: UserPool(
|
||||
password_policy=PasswordPolicy(
|
||||
temporary_password_validity_days=8,
|
||||
),
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=user_pool_id,
|
||||
arn=user_pool_arn,
|
||||
name=user_pool_name,
|
||||
last_modified=datetime.now(),
|
||||
creation_date=datetime.now(),
|
||||
status="ACTIVE",
|
||||
)
|
||||
}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_temporary_password_expiration.cognito_user_pool_temporary_password_expiration import (
|
||||
cognito_user_pool_temporary_password_expiration,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_temporary_password_expiration()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "FAIL"
|
||||
assert result[0].status_extended == (
|
||||
f"User pool {user_pool_name} has temporary password expiration set to 8 days."
|
||||
)
|
||||
|
||||
assert result[0].resource_id == user_pool_id
|
||||
assert result[0].resource_arn == user_pool_arn
|
||||
|
||||
def test_cognito_user_pools_password_expiration_7(self):
|
||||
cognito_client = mock.MagicMock
|
||||
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
|
||||
user_pool_name = "user_pool_name"
|
||||
user_pool_id = "eu-west-1_123456789"
|
||||
cognito_client.user_pools = {
|
||||
user_pool_arn: UserPool(
|
||||
password_policy=PasswordPolicy(
|
||||
temporary_password_validity_days=7,
|
||||
),
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=user_pool_id,
|
||||
arn=user_pool_arn,
|
||||
name=user_pool_name,
|
||||
last_modified=datetime.now(),
|
||||
creation_date=datetime.now(),
|
||||
status="ACTIVE",
|
||||
)
|
||||
}
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_temporary_password_expiration.cognito_user_pool_temporary_password_expiration import (
|
||||
cognito_user_pool_temporary_password_expiration,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_temporary_password_expiration()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "PASS"
|
||||
assert result[0].status_extended == (
|
||||
f"User pool {user_pool_name} has temporary password expiration set to 7 days."
|
||||
)
|
||||
|
||||
assert result[0].resource_id == user_pool_id
|
||||
assert result[0].resource_arn == user_pool_arn
|
||||
+146
@@ -0,0 +1,146 @@
|
||||
from datetime import datetime
|
||||
from unittest import mock
|
||||
|
||||
from prowler.providers.aws.services.cognito.cognito_service import UserPool
|
||||
from prowler.providers.aws.services.wafv2.wafv2_service import WebAclv2
|
||||
from tests.providers.aws.utils import AWS_ACCOUNT_NUMBER, AWS_REGION_US_EAST_1
|
||||
|
||||
|
||||
class Test_cognito_user_pool_waf_acl_attached:
|
||||
def test_cognito_no_user_pools(self):
|
||||
cognito_client = mock.MagicMock
|
||||
cognito_client.user_pools = {}
|
||||
cognito_client.audited_account = AWS_ACCOUNT_NUMBER
|
||||
wafv2_client = mock.MagicMock
|
||||
wafv2_client.web_acls = []
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.wafv2.wafv2_service.WAFv2",
|
||||
new=wafv2_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.wafv2.wafv2_client.wafv2_client",
|
||||
new=wafv2_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_waf_acl_attached.cognito_user_pool_waf_acl_attached import (
|
||||
cognito_user_pool_waf_acl_attached,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_waf_acl_attached()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 0
|
||||
|
||||
def test_cognito_no_web_acls(self):
|
||||
cognito_client = mock.MagicMock
|
||||
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
|
||||
user_pool_id = "eu-west-1_123456789"
|
||||
user_pool_name = "user_pool_name"
|
||||
cognito_client.user_pools = {
|
||||
user_pool_arn: UserPool(
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=user_pool_id,
|
||||
arn=user_pool_arn,
|
||||
name=user_pool_name,
|
||||
last_modified=datetime.now(),
|
||||
creation_date=datetime.now(),
|
||||
status="ACTIVE",
|
||||
)
|
||||
}
|
||||
cognito_client.audited_account = AWS_ACCOUNT_NUMBER
|
||||
wafv2_client = mock.MagicMock
|
||||
wafv2_client.web_acls = []
|
||||
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.wafv2.wafv2_service.WAFv2",
|
||||
new=wafv2_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.wafv2.wafv2_client.wafv2_client",
|
||||
new=wafv2_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_waf_acl_attached.cognito_user_pool_waf_acl_attached import (
|
||||
cognito_user_pool_waf_acl_attached,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_waf_acl_attached()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "FAIL"
|
||||
assert (
|
||||
result[0].status_extended
|
||||
== f"Cognito User Pool {user_pool_name} is not associated with a WAF Web ACL."
|
||||
)
|
||||
assert result[0].resource_id == user_pool_id
|
||||
assert result[0].resource_arn == user_pool_arn
|
||||
|
||||
def test_cognito_with_web_acls(self):
|
||||
cognito_client = mock.MagicMock
|
||||
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
|
||||
user_pool_id = "eu-west-1_123456789"
|
||||
user_pool_name = "user_pool_name"
|
||||
cognito_client.user_pools = {
|
||||
user_pool_arn: UserPool(
|
||||
region=AWS_REGION_US_EAST_1,
|
||||
id=user_pool_id,
|
||||
arn=user_pool_arn,
|
||||
name=user_pool_name,
|
||||
last_modified=datetime.now(),
|
||||
creation_date=datetime.now(),
|
||||
status="ACTIVE",
|
||||
)
|
||||
}
|
||||
cognito_client.audited_account = AWS_ACCOUNT_NUMBER
|
||||
wafv2_client = mock.MagicMock
|
||||
web_acl_arn = "arn:aws:wafv2:us-east-1:123456789012:regional/webacl/abcd1234"
|
||||
web_acl_name = "abcd1234"
|
||||
web_acl_id = "abcd1234"
|
||||
wafv2_client.web_acls = [
|
||||
WebAclv2(
|
||||
arn=web_acl_arn,
|
||||
name=web_acl_name,
|
||||
id=web_acl_id,
|
||||
albs=[],
|
||||
user_pools=[user_pool_arn],
|
||||
region="us-east-1",
|
||||
)
|
||||
]
|
||||
|
||||
with mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
|
||||
new=cognito_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.wafv2.wafv2_service.WAFv2",
|
||||
new=wafv2_client,
|
||||
), mock.patch(
|
||||
"prowler.providers.aws.services.wafv2.wafv2_client.wafv2_client",
|
||||
new=wafv2_client,
|
||||
):
|
||||
from prowler.providers.aws.services.cognito.cognito_user_pool_waf_acl_attached.cognito_user_pool_waf_acl_attached import (
|
||||
cognito_user_pool_waf_acl_attached,
|
||||
)
|
||||
|
||||
check = cognito_user_pool_waf_acl_attached()
|
||||
result = check.execute()
|
||||
|
||||
assert len(result) == 1
|
||||
assert result[0].status == "PASS"
|
||||
assert (
|
||||
result[0].status_extended
|
||||
== f"Cognito User Pool {user_pool_name} is associated with the WAF Web ACL {web_acl_name}."
|
||||
)
|
||||
assert result[0].resource_id == user_pool_id
|
||||
assert result[0].resource_arn == user_pool_arn
|
||||
@@ -101,3 +101,28 @@ class Test_WAFv2_Service:
|
||||
assert len(wafv2.web_acls) == 1
|
||||
assert len(wafv2.web_acls[0].albs) == 1
|
||||
assert lb["LoadBalancerArn"] in wafv2.web_acls[0].albs
|
||||
|
||||
# Test WAFv2 describe Web user pools
|
||||
@mock_aws
|
||||
def test__list_resources_for_web_user_pools__(self):
|
||||
wafv2 = client("wafv2", region_name=AWS_REGION_EU_WEST_1)
|
||||
cognito = client("cognito-idp", region_name=AWS_REGION_EU_WEST_1)
|
||||
waf = wafv2.create_web_acl(
|
||||
Scope="REGIONAL",
|
||||
Name="my-web-acl",
|
||||
DefaultAction={"Allow": {}},
|
||||
VisibilityConfig={
|
||||
"SampledRequestsEnabled": False,
|
||||
"CloudWatchMetricsEnabled": False,
|
||||
"MetricName": "idk",
|
||||
},
|
||||
)["Summary"]
|
||||
user_pool = cognito.create_user_pool(PoolName="my-user-pool")["UserPool"]
|
||||
wafv2.associate_web_acl(WebACLArn=waf["ARN"], ResourceArn=user_pool["Arn"])
|
||||
# WAFv2 client for this test class
|
||||
aws = set_mocked_aws_provider([AWS_REGION_EU_WEST_1])
|
||||
wafv2 = WAFv2(aws)
|
||||
wafv2.web_acls[0].user_pools.append(user_pool["Arn"])
|
||||
assert len(wafv2.web_acls) == 1
|
||||
assert len(wafv2.web_acls[0].user_pools) == 1
|
||||
assert user_pool["Arn"] in wafv2.web_acls[0].user_pools
|
||||
|
||||
+2
@@ -38,6 +38,7 @@ class Test_wafv2_webacl_logging_enabled:
|
||||
name=waf_name,
|
||||
id=waf_id,
|
||||
albs=[],
|
||||
user_pools=[],
|
||||
region=AWS_REGION_EU_WEST_1,
|
||||
logging_enabled=True,
|
||||
)
|
||||
@@ -75,6 +76,7 @@ class Test_wafv2_webacl_logging_enabled:
|
||||
name=waf_name,
|
||||
id=waf_id,
|
||||
albs=[],
|
||||
user_pools=[],
|
||||
region=AWS_REGION_EU_WEST_1,
|
||||
logging_enabled=False,
|
||||
)
|
||||
|
||||
Reference in New Issue
Block a user