feat(cognito): Add new checks related with cognito service (#3898)

This commit is contained in:
Pedro Martín
2024-05-08 17:25:57 +02:00
committed by GitHub
parent 73b7d76219
commit 225e12be91
74 changed files with 4022 additions and 18 deletions
@@ -0,0 +1,106 @@
from unittest import mock
from prowler.providers.aws.services.cognito.cognito_service import (
IdentityPool,
IdentityPoolRoles,
)
from tests.providers.aws.utils import AWS_ACCOUNT_NUMBER, AWS_REGION_US_EAST_1
class Test_cognito_identity_pool_guest_access_disabled:
def test_cognito_no_identity_pools(self):
cognito_identity_client = mock.MagicMock
cognito_identity_client.identity_pools = {}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIdentity",
cognito_identity_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_identity_client.cognito_identity_client",
new=cognito_identity_client,
):
from prowler.providers.aws.services.cognito.cognito_identity_pool_guest_access_disabled.cognito_identity_pool_guest_access_disabled import (
cognito_identity_pool_guest_access_disabled,
)
check = cognito_identity_pool_guest_access_disabled()
result = check.execute()
assert len(result) == 0
def test_cognito_identity_pools_guest_access_disabled(self):
cognito_identity_client = mock.MagicMock
identity_pool_arn = f"arn:aws:cognito-identity:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:identitypool/eu-west-1_123456789"
identity_pool_name = "identity_pool_name"
identity_pool_id = "eu-west-1_123456789"
cognito_identity_client.identity_pools = {
identity_pool_arn: IdentityPool(
allow_unauthenticated_identities=False,
region=AWS_REGION_US_EAST_1,
id=identity_pool_id,
arn=identity_pool_arn,
name=identity_pool_name,
)
}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIdentity",
cognito_identity_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_identity_client.cognito_identity_client",
new=cognito_identity_client,
):
from prowler.providers.aws.services.cognito.cognito_identity_pool_guest_access_disabled.cognito_identity_pool_guest_access_disabled import (
cognito_identity_pool_guest_access_disabled,
)
check = cognito_identity_pool_guest_access_disabled()
result = check.execute()
assert len(result) == 1
assert result[0].status == "PASS"
assert (
result[0].status_extended
== f"Identity pool {identity_pool_id} has guest access disabled."
)
assert result[0].resource_id == identity_pool_id
assert result[0].resource_arn == identity_pool_arn
def test_cognito_identity_pools_guest_access_enabled(self):
cognito_identity_client = mock.MagicMock
identity_pool_arn = f"arn:aws:cognito-identity:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:identitypool/eu-west-1_123456789"
identity_pool_name = "identity_pool_name"
identity_pool_id = "eu-west-1_123456789"
unauthenticated_role = "unauthenticated_role"
cognito_identity_client.identity_pools = {
identity_pool_arn: IdentityPool(
allow_unauthenticated_identities=True,
region=AWS_REGION_US_EAST_1,
id=identity_pool_id,
arn=identity_pool_arn,
name=identity_pool_name,
roles=IdentityPoolRoles(unauthenticated=unauthenticated_role),
)
}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIdentity",
cognito_identity_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_identity_client.cognito_identity_client",
new=cognito_identity_client,
):
from prowler.providers.aws.services.cognito.cognito_identity_pool_guest_access_disabled.cognito_identity_pool_guest_access_disabled import (
cognito_identity_pool_guest_access_disabled,
)
check = cognito_identity_pool_guest_access_disabled()
result = check.execute()
assert len(result) == 1
assert result[0].status == "FAIL"
assert (
result[0].status_extended
== f"Identity pool {identity_pool_name} has guest access enabled assuming the role {unauthenticated_role}."
)
assert result[0].resource_id == identity_pool_id
assert result[0].resource_arn == identity_pool_arn
@@ -1,7 +1,16 @@
import mock
from boto3 import client
from moto import mock_aws
from prowler.providers.aws.services.cognito.cognito_service import CognitoIDP
from prowler.providers.aws.services.cognito.cognito_service import (
AccountTakeoverRiskConfiguration,
CognitoIdentity,
CognitoIDP,
CompromisedCredentialsRiskConfiguration,
IdentityPoolRoles,
RiskConfiguration,
UserPoolClient,
)
from tests.providers.aws.utils import (
AWS_ACCOUNT_NUMBER,
AWS_REGION_EU_WEST_1,
@@ -13,7 +22,7 @@ from tests.providers.aws.utils import (
class Test_Cognito_Service:
# Test Cognito Service
@mock_aws
def test_service(self):
def test_service_idp(self):
aws_provider = set_mocked_aws_provider(
audited_regions=[AWS_REGION_EU_WEST_1, AWS_REGION_US_EAST_1]
)
@@ -22,7 +31,7 @@ class Test_Cognito_Service:
# Test Cognito client
@mock_aws
def test_client(self):
def test_client_idp(self):
aws_provider = set_mocked_aws_provider(
audited_regions=[AWS_REGION_EU_WEST_1, AWS_REGION_US_EAST_1]
)
@@ -32,7 +41,7 @@ class Test_Cognito_Service:
# Test Cognito session
@mock_aws
def test__get_session__(self):
def test__get_session_idp__(self):
aws_provider = set_mocked_aws_provider(
audited_regions=[AWS_REGION_EU_WEST_1, AWS_REGION_US_EAST_1]
)
@@ -41,7 +50,7 @@ class Test_Cognito_Service:
# Test Cognito Session
@mock_aws
def test_audited_account(self):
def test_audited_account_idp(self):
aws_provider = set_mocked_aws_provider(
audited_regions=[AWS_REGION_EU_WEST_1, AWS_REGION_US_EAST_1]
)
@@ -87,6 +96,112 @@ class Test_Cognito_Service:
assert user_pool.deletion_protection is not None
assert user_pool.advanced_security_mode is not None
assert user_pool.tags is not None
assert user_pool.account_recovery_settings is not None
assert user_pool.tags is not None
@mock_aws
def test_list_user_pool_clients(self):
cognito_client = mock.MagicMock()
user_pool_arn = "user_pool_test_1"
cognito_client[user_pool_arn].id = "user_pool_id"
cognito_client[user_pool_arn].arn = user_pool_arn
cognito_client[user_pool_arn].name = "user_pool_name"
cognito_client[user_pool_arn].region = "eu-west-1"
cognito_client[user_pool_arn].user_pool_clients["user_pool_client_id"] = (
UserPoolClient(
id="user_pool_client_id",
name="user_pool_client_name",
arn=f"{user_pool_arn}/client/user_pool_client_id",
region="eu-west-1",
)
)
with mock.patch(
"prowler.providers.common.common.get_global_provider",
return_value=set_mocked_aws_provider(),
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
for user_pool in cognito_client.user_pools.values():
assert user_pool.region == "eu-west-1"
assert user_pool.name == "user_pool_name"
assert user_pool.id == "user_pool_id"
assert (
user_pool.user_pool_clients["user_pool_client_id"].id
== "user_pool_client_id"
)
assert (
user_pool.user_pool_clients["user_pool_client_id"].name
== "user_pool_client_name"
)
assert (
user_pool.user_pool_clients["user_pool_client_id"].region
== "eu-west-1"
)
assert (
user_pool.user_pool_clients["user_pool_client_id"].arn
== f"{user_pool_arn}/client/user_pool_client_id"
)
@mock_aws
def test_describe_user_pool_clients(self):
cognito_client = mock.MagicMock()
user_pool_arn = "user_pool_test_1"
cognito_client[user_pool_arn].id = "user_pool_id"
cognito_client[user_pool_arn].arn = user_pool_arn
cognito_client[user_pool_arn].name = "user_pool_name"
cognito_client[user_pool_arn].region = "eu-west-1"
cognito_client[user_pool_arn].user_pool_clients["user_pool_client_id"] = (
UserPoolClient(
id="user_pool_client_id",
name="user_pool_client_name",
region="eu-west-1",
arn=f"{user_pool_arn}/client/user_pool_client_id",
prevent_user_existence_errors="ENABLED",
enable_token_revocation=True,
)
)
with mock.patch(
"prowler.providers.common.common.get_global_provider",
return_value=set_mocked_aws_provider(),
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
for user_pool in cognito_client.user_pools.values():
assert user_pool.region == "eu-west-1"
assert user_pool.name == "user_pool_name"
assert user_pool.id == "user_pool_id"
assert (
user_pool.user_pool_clients["user_pool_client_id"].id
== "user_pool_client_id"
)
assert (
user_pool.user_pool_clients["user_pool_client_id"].name
== "user_pool_client_name"
)
assert (
user_pool.user_pool_clients["user_pool_client_id"].region
== "eu-west-1"
)
assert (
user_pool.user_pool_clients["user_pool_client_id"].arn
== f"{user_pool_arn}/client/user_pool_client_id"
)
assert (
user_pool.user_pool_clients[
"user_pool_client_id"
].prevent_user_existence_errors
== "ENABLED"
)
assert (
user_pool.user_pool_clients[
"user_pool_client_id"
].enable_token_revocation
is True
)
@mock_aws
def test_get_user_pool_mfa_config(self):
@@ -115,3 +230,169 @@ class Test_Cognito_Service:
"Enabled": True
}
assert user_pool.mfa_config.status == "ON"
def test_get_user_pool_risk_configuration(self):
cognito_client = mock.MagicMock()
user_pool_arn = "user_pool_test_1"
cognito_client.user_pools[user_pool_arn].id = "user_pool_id"
cognito_client.user_pools[user_pool_arn].arn = user_pool_arn
cognito_client.user_pools[user_pool_arn].name = "user_pool_name"
cognito_client.user_pools[user_pool_arn].region = "eu-west-1"
cognito_client.user_pools[user_pool_arn].risk_configuration = RiskConfiguration(
compromised_credentials_risk_configuration=CompromisedCredentialsRiskConfiguration(
event_filter=["PASSWORD_CHANGE", "SIGN_UP", "SIGN_IN"],
actions="BLOCK",
),
account_takeover_risk_configuration=AccountTakeoverRiskConfiguration(
low_action="BLOCK",
medium_action="BLOCK",
high_action="BLOCK",
),
)
with mock.patch(
"prowler.providers.common.common.get_global_provider",
return_value=set_mocked_aws_provider(),
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
for user_pool in cognito_client.user_pools.values():
assert user_pool.region == "eu-west-1"
assert user_pool.name == "user_pool_name"
assert user_pool.id == "user_pool_id"
assert (
user_pool.risk_configuration.compromised_credentials_risk_configuration
== CompromisedCredentialsRiskConfiguration(
event_filter=["PASSWORD_CHANGE", "SIGN_UP", "SIGN_IN"],
actions="BLOCK",
)
)
assert (
user_pool.risk_configuration.account_takeover_risk_configuration.low_action
== "BLOCK"
)
assert (
user_pool.risk_configuration.account_takeover_risk_configuration.medium_action
== "BLOCK"
)
assert (
user_pool.risk_configuration.account_takeover_risk_configuration.high_action
== "BLOCK"
)
@mock_aws
def test_service_identity(self):
aws_provider = set_mocked_aws_provider(
audited_regions=[AWS_REGION_EU_WEST_1, AWS_REGION_US_EAST_1]
)
cognito = CognitoIdentity(aws_provider)
assert cognito.service == "cognito-identity"
# Test Cognito client
@mock_aws
def test_client_identity(self):
aws_provider = set_mocked_aws_provider(
audited_regions=[AWS_REGION_EU_WEST_1, AWS_REGION_US_EAST_1]
)
cognito = CognitoIdentity(aws_provider)
for regional_client in cognito.regional_clients.values():
assert regional_client.__class__.__name__ == "CognitoIdentity"
# Test Cognito session
@mock_aws
def test__get_session_identity__(self):
aws_provider = set_mocked_aws_provider(
audited_regions=[AWS_REGION_EU_WEST_1, AWS_REGION_US_EAST_1]
)
cognito = CognitoIdentity(aws_provider)
assert cognito.session.__class__.__name__ == "Session"
# Test Cognito Session
@mock_aws
def test_audited_account_identity(self):
aws_provider = set_mocked_aws_provider(
audited_regions=[AWS_REGION_EU_WEST_1, AWS_REGION_US_EAST_1]
)
cognito = CognitoIdentity(aws_provider)
assert cognito.audited_account == AWS_ACCOUNT_NUMBER
@mock_aws
def test_list_identity_pools(self):
identity_pool_name_1 = "identity_pool_test_1"
identity_pool_name_2 = "identity_pool_test_2"
aws_provider = set_mocked_aws_provider(
audited_regions=[AWS_REGION_EU_WEST_1, AWS_REGION_US_EAST_1]
)
cognito_client_eu_west_1 = client("cognito-identity", region_name="eu-west-1")
cognito_client_us_east_1 = client("cognito-identity", region_name="us-east-1")
cognito_client_eu_west_1.create_identity_pool(
IdentityPoolName=identity_pool_name_1, AllowUnauthenticatedIdentities=True
)
cognito_client_us_east_1.create_identity_pool(
IdentityPoolName=identity_pool_name_2, AllowUnauthenticatedIdentities=True
)
cognito = CognitoIdentity(aws_provider)
assert len(cognito.identity_pools) == 2
for identity_pool in cognito.identity_pools.values():
assert (
identity_pool.name == identity_pool_name_1
or identity_pool.name == identity_pool_name_2
)
assert (
identity_pool.region == "eu-west-1"
or identity_pool.region == "us-east-1"
)
@mock_aws
def test_describe_identity_pools(self):
identity_pool_name_1 = "identity_pool_test_1"
aws_provider = set_mocked_aws_provider(
audited_regions=[AWS_REGION_EU_WEST_1, AWS_REGION_US_EAST_1]
)
cognito_client_eu_west_1 = client("cognito-identity", region_name="eu-west-1")
identity_pool_id = cognito_client_eu_west_1.create_identity_pool(
IdentityPoolName=identity_pool_name_1, AllowUnauthenticatedIdentities=True
)["IdentityPoolId"]
cognito = CognitoIdentity(aws_provider)
assert len(cognito.identity_pools) == 1
for identity_pool in cognito.identity_pools.values():
assert identity_pool.name == identity_pool_name_1
assert identity_pool.region == "eu-west-1"
assert identity_pool.id == identity_pool_id
assert identity_pool.associated_pools is not None
assert identity_pool.tags is not None
assert identity_pool.allow_unauthenticated_identities is not None
@mock_aws
def test_get_identity_pool_tags(self):
cognito_identity_client = mock.MagicMock()
identity_pool_arn = "identity_pool_test_1"
cognito_identity_client[identity_pool_arn].id = "identity_pool_id"
cognito_identity_client[identity_pool_arn].arn = identity_pool_arn
cognito_identity_client[identity_pool_arn].name = "identity_pool_name"
cognito_identity_client[identity_pool_arn].region = "eu-west-1"
cognito_identity_client[identity_pool_arn].tags = {"tag_key": "tag_value"}
cognito_identity_client[identity_pool_arn].allow_unauthenticated_identities = (
True
)
cognito_identity_client[identity_pool_arn].roles = IdentityPoolRoles(
authenticated="authenticated_role",
unauthenticated="unauthenticated_role",
)
with mock.patch(
"prowler.providers.common.common.get_global_provider",
return_value=set_mocked_aws_provider(),
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_identity_client.cognito_identity_client",
new=cognito_identity_client,
):
for identity_pool in cognito_identity_client.identity_pools.values():
assert identity_pool.region == "eu-west-1"
assert identity_pool.name == "identity_pool_name"
assert identity_pool.id == "identity_pool_id"
assert identity_pool.tags == {"tag_key": "tag_value"}
assert identity_pool.allow_unauthenticated_identities is True
assert identity_pool.roles.authenticated == "authenticated_role"
assert identity_pool.roles.unauthenticated == "unauthenticated_role"
@@ -0,0 +1,146 @@
from datetime import datetime
from unittest import mock
from prowler.providers.aws.services.cognito.cognito_service import UserPool
from tests.providers.aws.utils import AWS_ACCOUNT_NUMBER, AWS_REGION_US_EAST_1
class Test_cognito_user_pool_advanced_security_enabled:
def test_cognito_no_user_pools(self):
cognito_client = mock.MagicMock
cognito_client.user_pools = {}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_advanced_security_enabled.cognito_user_pool_advanced_security_enabled import (
cognito_user_pool_advanced_security_enabled,
)
check = cognito_user_pool_advanced_security_enabled()
result = check.execute()
assert len(result) == 0
def test_cognito_user_pools_advanced_security_off(self):
cognito_client = mock.MagicMock
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
user_pool_name = "user_pool_name"
user_pool_id = "eu-west-1_123456789"
cognito_client.user_pools = {
user_pool_arn: UserPool(
advanced_security_mode="OFF",
region=AWS_REGION_US_EAST_1,
id=user_pool_id,
arn=user_pool_arn,
name=user_pool_name,
last_modified=datetime.now(),
creation_date=datetime.now(),
status="ACTIVE",
)
}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_advanced_security_enabled.cognito_user_pool_advanced_security_enabled import (
cognito_user_pool_advanced_security_enabled,
)
check = cognito_user_pool_advanced_security_enabled()
result = check.execute()
assert len(result) == 1
assert result[0].status == "FAIL"
assert result[0].status_extended == (
f"User pool {user_pool_name} has advanced security disabled."
)
assert result[0].resource_id == user_pool_id
assert result[0].resource_arn == user_pool_arn
def test_cognito_user_pools_advanced_security_audit(self):
cognito_client = mock.MagicMock
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
user_pool_name = "user_pool_name"
user_pool_id = "eu-west-1_123456789"
cognito_client.user_pools = {
user_pool_arn: UserPool(
advanced_security_mode="AUDIT",
region=AWS_REGION_US_EAST_1,
id=user_pool_id,
arn=user_pool_arn,
name=user_pool_name,
last_modified=datetime.now(),
creation_date=datetime.now(),
status="ACTIVE",
)
}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_advanced_security_enabled.cognito_user_pool_advanced_security_enabled import (
cognito_user_pool_advanced_security_enabled,
)
check = cognito_user_pool_advanced_security_enabled()
result = check.execute()
assert len(result) == 1
assert result[0].status == "FAIL"
assert result[0].status_extended == (
f"User pool {user_pool_name} has advanced security enabled but with audit-only mode."
)
assert result[0].resource_id == user_pool_id
assert result[0].resource_arn == user_pool_arn
def test_cognito_user_pools_advanced_security_enforced(self):
cognito_client = mock.MagicMock
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
user_pool_name = "user_pool_name"
user_pool_id = "eu-west-1_123456789"
cognito_client.user_pools = {
user_pool_arn: UserPool(
advanced_security_mode="ENFORCED",
region=AWS_REGION_US_EAST_1,
id=user_pool_id,
arn=user_pool_arn,
name=user_pool_name,
last_modified=datetime.now(),
creation_date=datetime.now(),
status="ACTIVE",
)
}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_advanced_security_enabled.cognito_user_pool_advanced_security_enabled import (
cognito_user_pool_advanced_security_enabled,
)
check = cognito_user_pool_advanced_security_enabled()
result = check.execute()
assert len(result) == 1
assert result[0].status == "PASS"
assert result[0].status_extended == (
f"User pool {user_pool_name} has advanced security enforced with full-function mode."
)
assert result[0].resource_id == user_pool_id
assert result[0].resource_arn == user_pool_arn
@@ -0,0 +1,210 @@
from datetime import datetime
from unittest import mock
from prowler.providers.aws.services.cognito.cognito_service import (
CompromisedCredentialsRiskConfiguration,
RiskConfiguration,
UserPool,
)
from tests.providers.aws.utils import AWS_ACCOUNT_NUMBER, AWS_REGION_US_EAST_1
class Test_cognito_user_pool_blocks_compromised_credentials_sign_in_attempts:
def test_cognito_no_user_pools(self):
cognito_client = mock.MagicMock
cognito_client.user_pools = {}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_blocks_compromised_credentials_sign_in_attempts.cognito_user_pool_blocks_compromised_credentials_sign_in_attempts import (
cognito_user_pool_blocks_compromised_credentials_sign_in_attempts,
)
check = cognito_user_pool_blocks_compromised_credentials_sign_in_attempts()
result = check.execute()
assert len(result) == 0
def test_cognito_user_pools_advanced_security_off(self):
cognito_client = mock.MagicMock
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
user_pool_name = "user_pool_name"
user_pool_id = "eu-west-1_123456789"
cognito_client.user_pools = {
user_pool_arn: UserPool(
advanced_security_mode="OFF",
risk_configuration=RiskConfiguration(
compromised_credentials_risk_configuration=CompromisedCredentialsRiskConfiguration(
event_filter=["SIGN_IN"],
actions="BLOCK",
)
),
region=AWS_REGION_US_EAST_1,
id=user_pool_id,
arn=user_pool_arn,
name=user_pool_name,
last_modified=datetime.now(),
creation_date=datetime.now(),
status="ACTIVE",
)
}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_blocks_compromised_credentials_sign_in_attempts.cognito_user_pool_blocks_compromised_credentials_sign_in_attempts import (
cognito_user_pool_blocks_compromised_credentials_sign_in_attempts,
)
check = cognito_user_pool_blocks_compromised_credentials_sign_in_attempts()
result = check.execute()
assert len(result) == 1
assert result[0].status == "FAIL"
assert result[0].status_extended == (
f"User pool {user_pool_name} does not block sign-in attempts with suspected compromised credentials."
)
assert result[0].resource_id == user_pool_id
assert result[0].resource_arn == user_pool_arn
def test_cognito_user_pools_advanced_security_audit(self):
cognito_client = mock.MagicMock
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
user_pool_name = "user_pool_name"
user_pool_id = "eu-west-1_123456789"
cognito_client.user_pools = {
user_pool_arn: UserPool(
advanced_security_mode="AUDIT",
risk_configuration=RiskConfiguration(
compromised_credentials_risk_configuration=CompromisedCredentialsRiskConfiguration(
event_filter=["SIGN_IN"],
actions="BLOCK",
)
),
region=AWS_REGION_US_EAST_1,
id=user_pool_id,
arn=user_pool_arn,
name=user_pool_name,
last_modified=datetime.now(),
creation_date=datetime.now(),
status="ACTIVE",
)
}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_blocks_compromised_credentials_sign_in_attempts.cognito_user_pool_blocks_compromised_credentials_sign_in_attempts import (
cognito_user_pool_blocks_compromised_credentials_sign_in_attempts,
)
check = cognito_user_pool_blocks_compromised_credentials_sign_in_attempts()
result = check.execute()
assert len(result) == 1
assert result[0].status == "FAIL"
assert result[0].status_extended == (
f"User pool {user_pool_name} does not block sign-in attempts with suspected compromised credentials."
)
assert result[0].resource_id == user_pool_id
assert result[0].resource_arn == user_pool_arn
def test_cognito_user_pools_advanced_security_enforced(self):
cognito_client = mock.MagicMock
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
user_pool_name = "user_pool_name"
user_pool_id = "eu-west-1_123456789"
cognito_client.user_pools = {
user_pool_arn: UserPool(
advanced_security_mode="ENFORCED",
risk_configuration=RiskConfiguration(
compromised_credentials_risk_configuration=CompromisedCredentialsRiskConfiguration(
event_filter=["SIGN_IN"],
actions="BLOCK",
)
),
region=AWS_REGION_US_EAST_1,
id=user_pool_id,
arn=user_pool_arn,
name=user_pool_name,
last_modified=datetime.now(),
creation_date=datetime.now(),
status="ACTIVE",
)
}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_blocks_compromised_credentials_sign_in_attempts.cognito_user_pool_blocks_compromised_credentials_sign_in_attempts import (
cognito_user_pool_blocks_compromised_credentials_sign_in_attempts,
)
check = cognito_user_pool_blocks_compromised_credentials_sign_in_attempts()
result = check.execute()
assert len(result) == 1
assert result[0].status == "PASS"
assert result[0].status_extended == (
f"User pool {user_pool_name} blocks sign-in attempts with suspected compromised credentials."
)
assert result[0].resource_id == user_pool_id
assert result[0].resource_arn == user_pool_arn
def test_cognito_user_pools_advanced_security_enforced_no_sign_in(self):
cognito_client = mock.MagicMock
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
user_pool_name = "user_pool_name"
user_pool_id = "eu-west-1_123456789"
cognito_client.user_pools = {
user_pool_arn: UserPool(
advanced_security_mode="ENFORCED",
risk_configuration=RiskConfiguration(
compromised_credentials_risk_configuration=CompromisedCredentialsRiskConfiguration(
event_filter=[],
actions="BLOCK",
)
),
region=AWS_REGION_US_EAST_1,
id=user_pool_id,
arn=user_pool_arn,
name=user_pool_name,
last_modified=datetime.now(),
creation_date=datetime.now(),
status="ACTIVE",
)
}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_blocks_compromised_credentials_sign_in_attempts.cognito_user_pool_blocks_compromised_credentials_sign_in_attempts import (
cognito_user_pool_blocks_compromised_credentials_sign_in_attempts,
)
check = cognito_user_pool_blocks_compromised_credentials_sign_in_attempts()
result = check.execute()
assert len(result) == 1
assert result[0].status == "FAIL"
assert result[0].status_extended == (
f"User pool {user_pool_name} does not block sign-in attempts with suspected compromised credentials."
)
assert result[0].resource_id == user_pool_id
assert result[0].resource_arn == user_pool_arn
@@ -0,0 +1,215 @@
from datetime import datetime
from unittest import mock
from prowler.providers.aws.services.cognito.cognito_service import (
AccountTakeoverRiskConfiguration,
RiskConfiguration,
UserPool,
)
from tests.providers.aws.utils import AWS_ACCOUNT_NUMBER, AWS_REGION_US_EAST_1
class Test_cognito_user_pool_blocks_potential_malicious_sign_in_attempts:
def test_cognito_no_user_pools(self):
cognito_client = mock.MagicMock
cognito_client.user_pools = {}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_blocks_potential_malicious_sign_in_attempts.cognito_user_pool_blocks_potential_malicious_sign_in_attempts import (
cognito_user_pool_blocks_potential_malicious_sign_in_attempts,
)
check = cognito_user_pool_blocks_potential_malicious_sign_in_attempts()
result = check.execute()
assert len(result) == 0
def test_cognito_user_pools_advanced_security_off(self):
cognito_client = mock.MagicMock
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
user_pool_name = "user_pool_name"
user_pool_id = "eu-west-1_123456789"
cognito_client.user_pools = {
user_pool_arn: UserPool(
advanced_security_mode="OFF",
risk_configuration=RiskConfiguration(
account_takeover_risk_configuration=AccountTakeoverRiskConfiguration(
low_action="BLOCK",
medium_action="BLOCK",
high_action="BLOCK",
)
),
region=AWS_REGION_US_EAST_1,
id=user_pool_id,
arn=user_pool_arn,
name=user_pool_name,
last_modified=datetime.now(),
creation_date=datetime.now(),
status="ACTIVE",
)
}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_blocks_potential_malicious_sign_in_attempts.cognito_user_pool_blocks_potential_malicious_sign_in_attempts import (
cognito_user_pool_blocks_potential_malicious_sign_in_attempts,
)
check = cognito_user_pool_blocks_potential_malicious_sign_in_attempts()
result = check.execute()
assert len(result) == 1
assert result[0].status == "FAIL"
assert result[0].status_extended == (
f"User pool {user_pool_name} does not block all potential malicious sign-in attempts."
)
assert result[0].resource_id == user_pool_id
assert result[0].resource_arn == user_pool_arn
def test_cognito_user_pools_advanced_security_audit(self):
cognito_client = mock.MagicMock
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
user_pool_name = "user_pool_name"
user_pool_id = "eu-west-1_123456789"
cognito_client.user_pools = {
user_pool_arn: UserPool(
advanced_security_mode="AUDIT",
risk_configuration=RiskConfiguration(
account_takeover_risk_configuration=AccountTakeoverRiskConfiguration(
low_action="BLOCK",
medium_action="BLOCK",
high_action="BLOCK",
)
),
region=AWS_REGION_US_EAST_1,
id=user_pool_id,
arn=user_pool_arn,
name=user_pool_name,
last_modified=datetime.now(),
creation_date=datetime.now(),
status="ACTIVE",
)
}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_blocks_potential_malicious_sign_in_attempts.cognito_user_pool_blocks_potential_malicious_sign_in_attempts import (
cognito_user_pool_blocks_potential_malicious_sign_in_attempts,
)
check = cognito_user_pool_blocks_potential_malicious_sign_in_attempts()
result = check.execute()
assert len(result) == 1
assert result[0].status == "FAIL"
assert result[0].status_extended == (
f"User pool {user_pool_name} does not block all potential malicious sign-in attempts."
)
assert result[0].resource_id == user_pool_id
assert result[0].resource_arn == user_pool_arn
def test_cognito_user_pools_advanced_security_enforced(self):
cognito_client = mock.MagicMock
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
user_pool_name = "user_pool_name"
user_pool_id = "eu-west-1_123456789"
cognito_client.user_pools = {
user_pool_arn: UserPool(
advanced_security_mode="ENFORCED",
risk_configuration=RiskConfiguration(
account_takeover_risk_configuration=AccountTakeoverRiskConfiguration(
low_action="BLOCK",
medium_action="BLOCK",
high_action="BLOCK",
)
),
region=AWS_REGION_US_EAST_1,
id=user_pool_id,
arn=user_pool_arn,
name=user_pool_name,
last_modified=datetime.now(),
creation_date=datetime.now(),
status="ACTIVE",
)
}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_blocks_potential_malicious_sign_in_attempts.cognito_user_pool_blocks_potential_malicious_sign_in_attempts import (
cognito_user_pool_blocks_potential_malicious_sign_in_attempts,
)
check = cognito_user_pool_blocks_potential_malicious_sign_in_attempts()
result = check.execute()
assert len(result) == 1
assert result[0].status == "PASS"
assert result[0].status_extended == (
f"User pool {user_pool_name} blocks all potential malicious sign-in attempts."
)
assert result[0].resource_id == user_pool_id
assert result[0].resource_arn == user_pool_arn
def test_cognito_user_pools_advanced_security_enforced_no_low_action(self):
cognito_client = mock.MagicMock
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
user_pool_name = "user_pool_name"
user_pool_id = "eu-west-1_123456789"
cognito_client.user_pools = {
user_pool_arn: UserPool(
advanced_security_mode="ENFORCED",
risk_configuration=RiskConfiguration(
account_takeover_risk_configuration=AccountTakeoverRiskConfiguration(
medium_action="BLOCK",
high_action="BLOCK",
)
),
region=AWS_REGION_US_EAST_1,
id=user_pool_id,
arn=user_pool_arn,
name=user_pool_name,
last_modified=datetime.now(),
creation_date=datetime.now(),
status="ACTIVE",
)
}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_blocks_potential_malicious_sign_in_attempts.cognito_user_pool_blocks_potential_malicious_sign_in_attempts import (
cognito_user_pool_blocks_potential_malicious_sign_in_attempts,
)
check = cognito_user_pool_blocks_potential_malicious_sign_in_attempts()
result = check.execute()
assert len(result) == 1
assert result[0].status == "FAIL"
assert result[0].status_extended == (
f"User pool {user_pool_name} does not block all potential malicious sign-in attempts."
)
assert result[0].resource_id == user_pool_id
assert result[0].resource_arn == user_pool_arn
@@ -0,0 +1,130 @@
from datetime import datetime
from unittest import mock
from prowler.providers.aws.services.cognito.cognito_service import (
UserPool,
UserPoolClient,
)
from tests.providers.aws.utils import AWS_ACCOUNT_NUMBER, AWS_REGION_US_EAST_1
class Test_cognito_user_pool_client_prevent_user_existence_errors:
def test_cognito_no_user_pools(self):
cognito_client = mock.MagicMock
cognito_client.user_pools = {}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_client_prevent_user_existence_errors.cognito_user_pool_client_prevent_user_existence_errors import (
cognito_user_pool_client_prevent_user_existence_errors,
)
check = cognito_user_pool_client_prevent_user_existence_errors()
result = check.execute()
assert len(result) == 0
def test_cognito_user_pools_prevent_user_existence_errors_disabled(self):
cognito_client = mock.MagicMock
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
user_pool_client_arn = f"{user_pool_arn}/client/eu-west-1_123456789"
user_pool_id = "eu-west-1_123456789"
user_pool_name = "eu-west-1_123456789"
user_pool_client_id = "eu-west-1_123456789"
user_pool_client_name = "eu-west-1_123456789"
cognito_client.user_pools = {
user_pool_arn: UserPool(
user_pool_clients={
user_pool_client_id: UserPoolClient(
id=user_pool_client_id,
name=user_pool_client_name,
region=AWS_REGION_US_EAST_1,
arn=user_pool_client_arn,
prevent_user_existence_errors="DISABLED",
)
},
region=AWS_REGION_US_EAST_1,
id=user_pool_id,
arn=user_pool_arn,
name=user_pool_name,
last_modified=datetime.now(),
creation_date=datetime.now(),
status="ACTIVE",
)
}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_client_prevent_user_existence_errors.cognito_user_pool_client_prevent_user_existence_errors import (
cognito_user_pool_client_prevent_user_existence_errors,
)
check = cognito_user_pool_client_prevent_user_existence_errors()
result = check.execute()
assert len(result) == 1
assert result[0].resource_id == user_pool_client_id
assert result[0].resource_arn == user_pool_client_arn
assert result[0].status == "FAIL"
assert result[0].status_extended == (
f"User pool client {user_pool_client_name} does not prevent revealing users in existence errors."
)
def test_cognito_user_pools_prevent_user_existence_errors_enabled(self):
cognito_client = mock.MagicMock
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
user_pool_client_arn = f"{user_pool_arn}/client/eu-west-1_123456789"
user_pool_id = "eu-west-1_123456789"
user_pool_name = "user_pool_name"
user_pool_client_id = "eu-west-1_123456789"
user_pool_client_name = "user_pool_name"
cognito_client.user_pools = {
user_pool_arn: UserPool(
user_pool_clients={
user_pool_client_id: UserPoolClient(
id=user_pool_client_id,
name=user_pool_client_name,
region=AWS_REGION_US_EAST_1,
arn=user_pool_client_arn,
prevent_user_existence_errors="ENABLED",
)
},
region=AWS_REGION_US_EAST_1,
id=user_pool_id,
arn=user_pool_arn,
name=user_pool_name,
last_modified=datetime.now(),
creation_date=datetime.now(),
status="ACTIVE",
)
}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_client_prevent_user_existence_errors.cognito_user_pool_client_prevent_user_existence_errors import (
cognito_user_pool_client_prevent_user_existence_errors,
)
check = cognito_user_pool_client_prevent_user_existence_errors()
result = check.execute()
assert len(result) == 1
assert result[0].status == "PASS"
assert result[0].status_extended == (
f"User pool client {user_pool_client_name} prevents revealing users in existence errors."
)
assert result[0].resource_id == user_pool_client_id
assert result[0].resource_arn == user_pool_client_arn
@@ -0,0 +1,131 @@
from datetime import datetime
from unittest import mock
from prowler.providers.aws.services.cognito.cognito_service import (
UserPool,
UserPoolClient,
)
from tests.providers.aws.utils import AWS_ACCOUNT_NUMBER, AWS_REGION_US_EAST_1
class Test_cognito_user_pool_client_token_revocation_enabled:
def test_cognito_no_user_pools(self):
cognito_client = mock.MagicMock
cognito_client.user_pools = {}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_client_token_revocation_enabled.cognito_user_pool_client_token_revocation_enabled import (
cognito_user_pool_client_token_revocation_enabled,
)
check = cognito_user_pool_client_token_revocation_enabled()
result = check.execute()
assert len(result) == 0
def test_cognito_user_pools_token_revocation_disabled(self):
cognito_client = mock.MagicMock
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
user_pool_name = "user_pool_name"
user_pool_id = "eu-west-1_123456789"
user_pool_client_id = "eu-west-1_123456789"
user_pool_client_name = "eu-west-1_123456789"
user_pool_client_arn = f"{user_pool_arn}/client/{user_pool_client_id}"
cognito_client.user_pools = {
user_pool_arn: UserPool(
user_pool_clients={
user_pool_client_id: UserPoolClient(
id=user_pool_client_id,
name=user_pool_client_name,
region=AWS_REGION_US_EAST_1,
arn=user_pool_client_arn,
enable_token_revocation=False,
)
},
region=AWS_REGION_US_EAST_1,
id=user_pool_id,
arn=user_pool_arn,
name=user_pool_name,
last_modified=datetime.now(),
creation_date=datetime.now(),
status="ACTIVE",
)
}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_client_token_revocation_enabled.cognito_user_pool_client_token_revocation_enabled import (
cognito_user_pool_client_token_revocation_enabled,
)
check = cognito_user_pool_client_token_revocation_enabled()
result = check.execute()
assert len(result) == 1
assert result[0].status == "FAIL"
assert result[0].status_extended == (
f"User pool client {user_pool_client_name} has token revocation disabled."
)
assert result[0].resource_id == user_pool_client_id
assert result[0].resource_arn == user_pool_client_arn
def test_project_user_pools_token_revocation_enabled(self):
cognito_client = mock.MagicMock
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
user_pool_name = "user_pool_name"
user_pool_id = "eu-west-1_123456789"
user_pool_client_id = "eu-west-1_123456789"
user_pool_client_name = "eu-west-1_123456789"
user_pool_client_arn = f"{user_pool_arn}/client/{user_pool_client_id}"
cognito_client.user_pools = {
user_pool_arn: UserPool(
user_pool_clients={
user_pool_client_id: UserPoolClient(
id=user_pool_client_id,
name=user_pool_client_name,
arn=user_pool_client_arn,
region=AWS_REGION_US_EAST_1,
enable_token_revocation=True,
)
},
region=AWS_REGION_US_EAST_1,
id=user_pool_id,
arn=user_pool_arn,
name=user_pool_name,
last_modified=datetime.now(),
creation_date=datetime.now(),
status="ACTIVE",
)
}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_client_token_revocation_enabled.cognito_user_pool_client_token_revocation_enabled import (
cognito_user_pool_client_token_revocation_enabled,
)
check = cognito_user_pool_client_token_revocation_enabled()
result = check.execute()
assert len(result) == 1
assert result[0].status == "PASS"
assert result[0].status_extended == (
f"User pool client {user_pool_client_name} has token revocation enabled."
)
assert result[0].resource_id == user_pool_client_id
assert result[0].resource_arn == user_pool_client_arn
@@ -0,0 +1,105 @@
from datetime import datetime
from unittest import mock
from prowler.providers.aws.services.cognito.cognito_service import UserPool
from tests.providers.aws.utils import AWS_ACCOUNT_NUMBER, AWS_REGION_US_EAST_1
class Test_cognito_user_pool_deletion_protection_enabled:
def test_cognito_no_user_pools(self):
cognito_client = mock.MagicMock
cognito_client.user_pools = {}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_deletion_protection_enabled.cognito_user_pool_deletion_protection_enabled import (
cognito_user_pool_deletion_protection_enabled,
)
check = cognito_user_pool_deletion_protection_enabled()
result = check.execute()
assert len(result) == 0
def test_cognito_user_pools_deletion_protection_disabled(self):
cognito_client = mock.MagicMock
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
user_pool_name = "user_pool_name"
user_pool_id = "eu-west-1_123456789"
cognito_client.user_pools = {
user_pool_arn: UserPool(
deletion_protection="DISABLED",
region=AWS_REGION_US_EAST_1,
id=user_pool_id,
arn=user_pool_arn,
name=user_pool_name,
last_modified=datetime.now(),
creation_date=datetime.now(),
status="ACTIVE",
)
}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_deletion_protection_enabled.cognito_user_pool_deletion_protection_enabled import (
cognito_user_pool_deletion_protection_enabled,
)
check = cognito_user_pool_deletion_protection_enabled()
result = check.execute()
assert len(result) == 1
assert result[0].status == "FAIL"
assert result[0].status_extended == (
f"User pool {user_pool_name} has deletion protection disabled."
)
assert result[0].resource_id == user_pool_id
assert result[0].resource_arn == user_pool_arn
def test_cognito_user_pools_deletion_protection_enabled(self):
cognito_client = mock.MagicMock
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
user_pool_name = "user_pool_name"
user_pool_id = "eu-west-1_123456789"
cognito_client.user_pools = {
user_pool_arn: UserPool(
deletion_protection="ACTIVE",
region=AWS_REGION_US_EAST_1,
id=user_pool_id,
arn=user_pool_arn,
name=user_pool_name,
last_modified=datetime.now(),
creation_date=datetime.now(),
status="ACTIVE",
)
}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_deletion_protection_enabled.cognito_user_pool_deletion_protection_enabled import (
cognito_user_pool_deletion_protection_enabled,
)
check = cognito_user_pool_deletion_protection_enabled()
result = check.execute()
assert len(result) == 1
assert result[0].status == "PASS"
assert result[0].status_extended == (
f"User pool {user_pool_name} has deletion protection enabled."
)
assert result[0].resource_id == user_pool_id
assert result[0].resource_arn == user_pool_arn
@@ -0,0 +1,146 @@
from datetime import datetime
from unittest import mock
from prowler.providers.aws.services.cognito.cognito_service import UserPool
from tests.providers.aws.utils import AWS_ACCOUNT_NUMBER, AWS_REGION_US_EAST_1
class Test_cognito_user_pool_mfa_enabled:
def test_cognito_no_user_pools(self):
cognito_client = mock.MagicMock
cognito_client.user_pools = {}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_mfa_enabled.cognito_user_pool_mfa_enabled import (
cognito_user_pool_mfa_enabled,
)
check = cognito_user_pool_mfa_enabled()
result = check.execute()
assert len(result) == 0
def test_cognito_user_pools_mfa_config_none(self):
cognito_client = mock.MagicMock
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
user_pool_id = "eu-west-1_123456789"
user_pool_name = "user_pool_name"
cognito_client.user_pools = {
user_pool_arn: UserPool(
mfa_config=None,
region=AWS_REGION_US_EAST_1,
id=user_pool_id,
arn=user_pool_arn,
name=user_pool_name,
last_modified=datetime.now(),
creation_date=datetime.now(),
status="ACTIVE",
)
}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_mfa_enabled.cognito_user_pool_mfa_enabled import (
cognito_user_pool_mfa_enabled,
)
check = cognito_user_pool_mfa_enabled()
result = check.execute()
assert len(result) == 1
assert result[0].status == "FAIL"
assert result[0].status_extended == (
f"User pool {user_pool_name} has MFA disabled."
)
assert result[0].resource_id == user_pool_id
assert result[0].resource_arn == user_pool_arn
def test_cognito_user_pools_mfa_config_disabled(self):
cognito_client = mock.MagicMock
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
user_pool_id = "eu-west-1_123456789"
user_pool_name = "user_pool_name"
cognito_client.user_pools = {
user_pool_arn: UserPool(
mfa_config={"status": "OFF"},
region=AWS_REGION_US_EAST_1,
id=user_pool_id,
arn=user_pool_arn,
name=user_pool_name,
last_modified=datetime.now(),
creation_date=datetime.now(),
status="ACTIVE",
)
}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_mfa_enabled.cognito_user_pool_mfa_enabled import (
cognito_user_pool_mfa_enabled,
)
check = cognito_user_pool_mfa_enabled()
result = check.execute()
assert len(result) == 1
assert result[0].status == "FAIL"
assert result[0].status_extended == (
f"User pool {user_pool_name} has MFA disabled."
)
assert result[0].resource_id == user_pool_id
assert result[0].resource_arn == user_pool_arn
def test_cognito_user_pools_mfa_config_enabled(self):
cognito_client = mock.MagicMock
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
user_pool_id = "eu-west-1_123456789"
user_pool_name = "user_pool_name"
cognito_client.user_pools = {
user_pool_arn: UserPool(
mfa_config={"status": "ON"},
region=AWS_REGION_US_EAST_1,
id=user_pool_id,
arn=user_pool_arn,
name=user_pool_name,
last_modified=datetime.now(),
creation_date=datetime.now(),
status="ACTIVE",
)
}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_mfa_enabled.cognito_user_pool_mfa_enabled import (
cognito_user_pool_mfa_enabled,
)
check = cognito_user_pool_mfa_enabled()
result = check.execute()
assert len(result) == 1
assert result[0].status == "PASS"
assert result[0].status_extended == (
f"User pool {user_pool_name} has MFA enabled."
)
assert result[0].resource_id == user_pool_id
assert result[0].resource_arn == user_pool_arn
@@ -0,0 +1,153 @@
from datetime import datetime
from unittest import mock
from prowler.providers.aws.services.cognito.cognito_service import (
PasswordPolicy,
UserPool,
)
from tests.providers.aws.utils import AWS_ACCOUNT_NUMBER, AWS_REGION_US_EAST_1
class Test_cognito_user_pool_password_policy_lowercase:
def test_cognito_no_user_pools(self):
cognito_client = mock.MagicMock
cognito_client.user_pools = {}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_password_policy_lowercase.cognito_user_pool_password_policy_lowercase import (
cognito_user_pool_password_policy_lowercase,
)
check = cognito_user_pool_password_policy_lowercase()
result = check.execute()
assert len(result) == 0
def test_cognito_user_pools_bad_password_policy(self):
cognito_client = mock.MagicMock
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
user_pool_id = "eu-west-1_123456789"
user_pool_name = "user_pool_name"
cognito_client.user_pools = {
user_pool_arn: UserPool(
password_policy=PasswordPolicy(
require_lowercase=False,
),
region=AWS_REGION_US_EAST_1,
id=user_pool_id,
arn=user_pool_arn,
name=user_pool_name,
last_modified=datetime.now(),
creation_date=datetime.now(),
status="ACTIVE",
)
}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_password_policy_lowercase.cognito_user_pool_password_policy_lowercase import (
cognito_user_pool_password_policy_lowercase,
)
check = cognito_user_pool_password_policy_lowercase()
result = check.execute()
assert len(result) == 1
assert result[0].status == "FAIL"
assert result[0].status_extended == (
f"User pool {user_pool_name} does not have a password policy with a lowercase requirement."
)
assert result[0].resource_id == user_pool_id
assert result[0].resource_arn == user_pool_arn
def test_cognito_user_pools_good_password_policy(self):
cognito_client = mock.MagicMock
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
user_pool_id = "eu-west-1_123456789"
user_pool_name = "user_pool_name"
cognito_client.user_pools = {
user_pool_arn: UserPool(
password_policy=PasswordPolicy(
require_lowercase=True,
),
region=AWS_REGION_US_EAST_1,
id=user_pool_id,
arn=user_pool_arn,
name=user_pool_name,
last_modified=datetime.now(),
creation_date=datetime.now(),
status="ACTIVE",
)
}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_password_policy_lowercase.cognito_user_pool_password_policy_lowercase import (
cognito_user_pool_password_policy_lowercase,
)
check = cognito_user_pool_password_policy_lowercase()
result = check.execute()
assert len(result) == 1
assert result[0].status == "PASS"
assert result[0].status_extended == (
f"User pool {user_pool_name} has a password policy with a lowercase requirement."
)
assert result[0].resource_id == user_pool_id
assert result[0].resource_arn == user_pool_arn
def test_cognito_user_pools_no_password_policy(self):
cognito_client = mock.MagicMock
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
user_pool_id = "eu-west-1_123456789"
user_pool_name = "user_pool_name"
cognito_client.user_pools = {
user_pool_arn: UserPool(
password_policy=None,
region=AWS_REGION_US_EAST_1,
id=user_pool_id,
arn=user_pool_arn,
name=user_pool_name,
last_modified=datetime.now(),
creation_date=datetime.now(),
status="ACTIVE",
)
}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_password_policy_lowercase.cognito_user_pool_password_policy_lowercase import (
cognito_user_pool_password_policy_lowercase,
)
check = cognito_user_pool_password_policy_lowercase()
result = check.execute()
assert len(result) == 1
assert result[0].status == "FAIL"
assert result[0].status_extended == (
f"User pool {user_pool_name} has not a password policy set."
)
assert result[0].resource_id == user_pool_id
assert result[0].resource_arn == user_pool_arn
@@ -0,0 +1,153 @@
from datetime import datetime
from unittest import mock
from prowler.providers.aws.services.cognito.cognito_service import (
PasswordPolicy,
UserPool,
)
from tests.providers.aws.utils import AWS_ACCOUNT_NUMBER, AWS_REGION_US_EAST_1
class Test_cognito_user_pool_password_policy_minimum_length_14:
def test_cognito_no_user_pools(self):
cognito_client = mock.MagicMock
cognito_client.user_pools = {}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_password_policy_minimum_length_14.cognito_user_pool_password_policy_minimum_length_14 import (
cognito_user_pool_password_policy_minimum_length_14,
)
check = cognito_user_pool_password_policy_minimum_length_14()
result = check.execute()
assert len(result) == 0
def test_cognito_user_pools_bad_password_policy(self):
cognito_client = mock.MagicMock
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
user_pool_id = "eu-west-1_123456789"
user_pool_name = "user_pool_name"
cognito_client.user_pools = {
user_pool_arn: UserPool(
password_policy=PasswordPolicy(
minimum_length=10,
),
region=AWS_REGION_US_EAST_1,
id=user_pool_id,
arn=user_pool_arn,
name=user_pool_name,
last_modified=datetime.now(),
creation_date=datetime.now(),
status="ACTIVE",
)
}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_password_policy_minimum_length_14.cognito_user_pool_password_policy_minimum_length_14 import (
cognito_user_pool_password_policy_minimum_length_14,
)
check = cognito_user_pool_password_policy_minimum_length_14()
result = check.execute()
assert len(result) == 1
assert result[0].status == "FAIL"
assert result[0].status_extended == (
f"User pool {user_pool_name} does not have a password policy with a minimum length of 14 characters."
)
assert result[0].resource_id == user_pool_id
assert result[0].resource_arn == user_pool_arn
def test_cognito_user_pools_good_password_policy(self):
cognito_client = mock.MagicMock
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
user_pool_id = "eu-west-1_123456789"
user_pool_name = "user_pool_name"
cognito_client.user_pools = {
user_pool_arn: UserPool(
password_policy=PasswordPolicy(
minimum_length=14,
),
region=AWS_REGION_US_EAST_1,
id=user_pool_id,
arn=user_pool_arn,
name=user_pool_name,
last_modified=datetime.now(),
creation_date=datetime.now(),
status="ACTIVE",
)
}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_password_policy_minimum_length_14.cognito_user_pool_password_policy_minimum_length_14 import (
cognito_user_pool_password_policy_minimum_length_14,
)
check = cognito_user_pool_password_policy_minimum_length_14()
result = check.execute()
assert len(result) == 1
assert result[0].status == "PASS"
assert result[0].status_extended == (
f"User pool {user_pool_name} has a password policy with a minimum length of 14 characters."
)
assert result[0].resource_id == user_pool_id
assert result[0].resource_arn == user_pool_arn
def test_cognito_user_pools_no_password_policy(self):
cognito_client = mock.MagicMock
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
user_pool_id = "eu-west-1_123456789"
user_pool_name = "user_pool_name"
cognito_client.user_pools = {
user_pool_arn: UserPool(
password_policy=None,
region=AWS_REGION_US_EAST_1,
id=user_pool_id,
arn=user_pool_arn,
name=user_pool_name,
last_modified=datetime.now(),
creation_date=datetime.now(),
status="ACTIVE",
)
}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_password_policy_minimum_length_14.cognito_user_pool_password_policy_minimum_length_14 import (
cognito_user_pool_password_policy_minimum_length_14,
)
check = cognito_user_pool_password_policy_minimum_length_14()
result = check.execute()
assert len(result) == 1
assert result[0].status == "FAIL"
assert result[0].status_extended == (
f"User pool {user_pool_name} has not a password policy set."
)
assert result[0].resource_id == user_pool_id
assert result[0].resource_arn == user_pool_arn
@@ -0,0 +1,153 @@
from datetime import datetime
from unittest import mock
from prowler.providers.aws.services.cognito.cognito_service import (
PasswordPolicy,
UserPool,
)
from tests.providers.aws.utils import AWS_ACCOUNT_NUMBER, AWS_REGION_US_EAST_1
class Test_cognito_user_pool_password_policy_number:
def test_cognito_no_user_pools(self):
cognito_client = mock.MagicMock
cognito_client.user_pools = {}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_password_policy_number.cognito_user_pool_password_policy_number import (
cognito_user_pool_password_policy_number,
)
check = cognito_user_pool_password_policy_number()
result = check.execute()
assert len(result) == 0
def test_cognito_user_pools_bad_password_policy(self):
cognito_client = mock.MagicMock
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
user_pool_id = "eu-west-1_123456789"
user_pool_name = "user_pool_name"
cognito_client.user_pools = {
user_pool_arn: UserPool(
password_policy={
"RequireNumbers": False,
},
region=AWS_REGION_US_EAST_1,
id=user_pool_id,
arn=user_pool_arn,
name=user_pool_name,
last_modified=datetime.now(),
creation_date=datetime.now(),
status="ACTIVE",
)
}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_password_policy_number.cognito_user_pool_password_policy_number import (
cognito_user_pool_password_policy_number,
)
check = cognito_user_pool_password_policy_number()
result = check.execute()
assert len(result) == 1
assert result[0].status == "FAIL"
assert result[0].status_extended == (
f"User pool {user_pool_name} does not have a password policy with a number requirement."
)
assert result[0].resource_id == user_pool_id
assert result[0].resource_arn == user_pool_arn
def test_cognito_user_pools_good_password_policy(self):
cognito_client = mock.MagicMock
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
user_pool_id = "eu-west-1_123456789"
user_pool_name = "user_pool_name"
cognito_client.user_pools = {
user_pool_arn: UserPool(
password_policy=PasswordPolicy(
require_numbers=True,
),
region=AWS_REGION_US_EAST_1,
id=user_pool_id,
arn=user_pool_arn,
name=user_pool_name,
last_modified=datetime.now(),
creation_date=datetime.now(),
status="ACTIVE",
)
}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_password_policy_number.cognito_user_pool_password_policy_number import (
cognito_user_pool_password_policy_number,
)
check = cognito_user_pool_password_policy_number()
result = check.execute()
assert len(result) == 1
assert result[0].status == "PASS"
assert result[0].status_extended == (
f"User pool {user_pool_name} has a password policy with a number requirement."
)
assert result[0].resource_id == user_pool_id
assert result[0].resource_arn == user_pool_arn
def test_cognito_user_pools_no_password_policy(self):
cognito_client = mock.MagicMock
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
user_pool_id = "eu-west-1_123456789"
user_pool_name = "user_pool_name"
cognito_client.user_pools = {
user_pool_arn: UserPool(
password_policy=None,
region=AWS_REGION_US_EAST_1,
id=user_pool_id,
arn=user_pool_arn,
name=user_pool_name,
last_modified=datetime.now(),
creation_date=datetime.now(),
status="ACTIVE",
)
}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_password_policy_number.cognito_user_pool_password_policy_number import (
cognito_user_pool_password_policy_number,
)
check = cognito_user_pool_password_policy_number()
result = check.execute()
assert len(result) == 1
assert result[0].status == "FAIL"
assert result[0].status_extended == (
f"User pool {user_pool_name} has not a password policy set."
)
assert result[0].resource_id == user_pool_id
assert result[0].resource_arn == user_pool_arn
@@ -0,0 +1,153 @@
from datetime import datetime
from unittest import mock
from prowler.providers.aws.services.cognito.cognito_service import (
PasswordPolicy,
UserPool,
)
from tests.providers.aws.utils import AWS_ACCOUNT_NUMBER, AWS_REGION_US_EAST_1
class Test_cognito_user_pool_password_policy_symbol:
def test_cognito_no_user_pools(self):
cognito_client = mock.MagicMock
cognito_client.user_pools = {}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_password_policy_symbol.cognito_user_pool_password_policy_symbol import (
cognito_user_pool_password_policy_symbol,
)
check = cognito_user_pool_password_policy_symbol()
result = check.execute()
assert len(result) == 0
def test_cognito_user_pools_bad_password_policy(self):
cognito_client = mock.MagicMock
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
user_pool_id = "eu-west-1_123456789"
user_pool_name = "user_pool_name"
cognito_client.user_pools = {
user_pool_arn: UserPool(
password_policy=PasswordPolicy(
require_symbols=False,
),
region=AWS_REGION_US_EAST_1,
id=user_pool_id,
arn=user_pool_arn,
name=user_pool_name,
last_modified=datetime.now(),
creation_date=datetime.now(),
status="ACTIVE",
)
}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_password_policy_symbol.cognito_user_pool_password_policy_symbol import (
cognito_user_pool_password_policy_symbol,
)
check = cognito_user_pool_password_policy_symbol()
result = check.execute()
assert len(result) == 1
assert result[0].status == "FAIL"
assert result[0].status_extended == (
f"User pool {user_pool_name} does not have a password policy with a symbol requirement."
)
assert result[0].resource_id == user_pool_id
assert result[0].resource_arn == user_pool_arn
def test_cognito_user_pools_good_password_policy(self):
cognito_client = mock.MagicMock
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
user_pool_id = "eu-west-1_123456789"
user_pool_name = "user_pool_name"
cognito_client.user_pools = {
user_pool_arn: UserPool(
password_policy=PasswordPolicy(
require_symbols=True,
),
region=AWS_REGION_US_EAST_1,
id=user_pool_id,
arn=user_pool_arn,
name=user_pool_name,
last_modified=datetime.now(),
creation_date=datetime.now(),
status="ACTIVE",
)
}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_password_policy_symbol.cognito_user_pool_password_policy_symbol import (
cognito_user_pool_password_policy_symbol,
)
check = cognito_user_pool_password_policy_symbol()
result = check.execute()
assert len(result) == 1
assert result[0].status == "PASS"
assert result[0].status_extended == (
f"User pool {user_pool_name} has a password policy with a symbol requirement."
)
assert result[0].resource_id == user_pool_id
assert result[0].resource_arn == user_pool_arn
def test_cognito_user_pools_no_password_policy(self):
cognito_client = mock.MagicMock
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
user_pool_id = "eu-west-1_123456789"
user_pool_name = "user_pool_name"
cognito_client.user_pools = {
user_pool_arn: UserPool(
password_policy=None,
region=AWS_REGION_US_EAST_1,
id=user_pool_id,
arn=user_pool_arn,
name=user_pool_name,
last_modified=datetime.now(),
creation_date=datetime.now(),
status="ACTIVE",
)
}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_password_policy_symbol.cognito_user_pool_password_policy_symbol import (
cognito_user_pool_password_policy_symbol,
)
check = cognito_user_pool_password_policy_symbol()
result = check.execute()
assert len(result) == 1
assert result[0].status == "FAIL"
assert result[0].status_extended == (
f"User pool {user_pool_name} has not a password policy set."
)
assert result[0].resource_id == user_pool_id
assert result[0].resource_arn == user_pool_arn
@@ -0,0 +1,153 @@
from datetime import datetime
from unittest import mock
from prowler.providers.aws.services.cognito.cognito_service import (
PasswordPolicy,
UserPool,
)
from tests.providers.aws.utils import AWS_ACCOUNT_NUMBER, AWS_REGION_US_EAST_1
class Test_cognito_user_pool_password_policy_uppercase:
def test_cognito_no_user_pools(self):
cognito_client = mock.MagicMock
cognito_client.user_pools = {}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_password_policy_uppercase.cognito_user_pool_password_policy_uppercase import (
cognito_user_pool_password_policy_uppercase,
)
check = cognito_user_pool_password_policy_uppercase()
result = check.execute()
assert len(result) == 0
def test_cognito_user_pools_bad_password_policy(self):
cognito_client = mock.MagicMock
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
user_pool_id = "eu-west-1_123456789"
user_pool_name = "user_pool_name"
cognito_client.user_pools = {
user_pool_arn: UserPool(
password_policy=PasswordPolicy(
require_uppercase=False,
),
region=AWS_REGION_US_EAST_1,
id=user_pool_id,
arn=user_pool_arn,
name=user_pool_name,
last_modified=datetime.now(),
creation_date=datetime.now(),
status="ACTIVE",
)
}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_password_policy_uppercase.cognito_user_pool_password_policy_uppercase import (
cognito_user_pool_password_policy_uppercase,
)
check = cognito_user_pool_password_policy_uppercase()
result = check.execute()
assert len(result) == 1
assert result[0].status == "FAIL"
assert result[0].status_extended == (
f"User pool {user_pool_name} does not have a password policy with an uppercase requirement."
)
assert result[0].resource_id == user_pool_id
assert result[0].resource_arn == user_pool_arn
def test_cognito_user_pools_good_password_policy(self):
cognito_client = mock.MagicMock
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
user_pool_id = "eu-west-1_123456789"
user_pool_name = "user_pool_name"
cognito_client.user_pools = {
user_pool_arn: UserPool(
password_policy=PasswordPolicy(
require_uppercase=True,
),
region=AWS_REGION_US_EAST_1,
id=user_pool_id,
arn=user_pool_arn,
name=user_pool_name,
last_modified=datetime.now(),
creation_date=datetime.now(),
status="ACTIVE",
)
}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_password_policy_uppercase.cognito_user_pool_password_policy_uppercase import (
cognito_user_pool_password_policy_uppercase,
)
check = cognito_user_pool_password_policy_uppercase()
result = check.execute()
assert len(result) == 1
assert result[0].status == "PASS"
assert result[0].status_extended == (
f"User pool {user_pool_name} has a password policy with an uppercase requirement."
)
assert result[0].resource_id == user_pool_id
assert result[0].resource_arn == user_pool_arn
def test_cognito_user_pools_no_password_policy(self):
cognito_client = mock.MagicMock
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
user_pool_id = "eu-west-1_123456789"
user_pool_name = "user_pool_name"
cognito_client.user_pools = {
user_pool_arn: UserPool(
password_policy=None,
region=AWS_REGION_US_EAST_1,
id=user_pool_id,
arn=user_pool_arn,
name=user_pool_name,
last_modified=datetime.now(),
creation_date=datetime.now(),
status="ACTIVE",
)
}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_password_policy_uppercase.cognito_user_pool_password_policy_uppercase import (
cognito_user_pool_password_policy_uppercase,
)
check = cognito_user_pool_password_policy_uppercase()
result = check.execute()
assert len(result) == 1
assert result[0].status == "FAIL"
assert result[0].status_extended == (
f"User pool {user_pool_name} has not a password policy set."
)
assert result[0].resource_id == user_pool_id
assert result[0].resource_arn == user_pool_arn
@@ -0,0 +1,227 @@
from datetime import datetime
from unittest import mock
from prowler.providers.aws.services.cognito.cognito_service import (
AdminCreateUserConfig,
IdentityPool,
IdentityPoolRoles,
UserPool,
)
from tests.providers.aws.utils import AWS_ACCOUNT_NUMBER, AWS_REGION_US_EAST_1
class Test_cognito_user_pool_self_registration_disabled:
def test_cognito_no_user_pools(self):
cognito_client = mock.MagicMock
cognito_client.user_pools = {}
cognito_identity_client = mock.MagicMock
cognito_identity_client.identity_pools = {}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIdentity",
cognito_identity_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_identity_client.cognito_identity_client",
cognito_identity_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_self_registration_disabled.cognito_user_pool_self_registration_disabled import (
cognito_user_pool_self_registration_disabled,
)
check = cognito_user_pool_self_registration_disabled()
result = check.execute()
assert len(result) == 0
def test_cognito_no_identity_pools(self):
cognito_client = mock.MagicMock
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
user_pool_id = "eu-west-1_123456789"
user_pool_name = "eu-west-1_123456789"
cognito_client.user_pools = {
user_pool_arn: UserPool(
admin_create_user_config=AdminCreateUserConfig(
allow_admin_create_user_only=False
),
region=AWS_REGION_US_EAST_1,
id=user_pool_id,
arn=user_pool_arn,
name=user_pool_name,
last_modified=datetime.now(),
creation_date=datetime.now(),
status="ACTIVE",
)
}
cognito_identity_client = mock.MagicMock
cognito_identity_client.identity_pools = {}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIdentity",
cognito_identity_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_identity_client.cognito_identity_client",
cognito_identity_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_self_registration_disabled.cognito_user_pool_self_registration_disabled import (
cognito_user_pool_self_registration_disabled,
)
check = cognito_user_pool_self_registration_disabled()
result = check.execute()
assert len(result) == 1
assert result[0].status == "FAIL"
assert result[0].status_extended == (
f"User pool {user_pool_name} has self registration enabled."
)
assert result[0].resource_id == user_pool_id
assert result[0].resource_arn == user_pool_arn
def test_cognito_identity_pools_allow_admin_create_user_enabled(self):
cognito_client = mock.MagicMock
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
user_pool_id = "eu-west-1_123456789"
user_pool_name = "eu-west-1_123456789"
cognito_client.user_pools = {
user_pool_arn: UserPool(
admin_create_user_config=AdminCreateUserConfig(
allow_admin_create_user_only=True
),
region=AWS_REGION_US_EAST_1,
id=user_pool_id,
arn=user_pool_arn,
name=user_pool_name,
last_modified=datetime.now(),
creation_date=datetime.now(),
status="ACTIVE",
)
}
cognito_identity_client = mock.MagicMock
identity_pool_name = "identity_pool_name"
identity_pool_id = "eu-west-1_123456789"
identity_pool_arn = f"arn:aws:cognito-identity:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:identitypool/eu-west-1_123456789"
authenticated_role = "authenticated_role"
cognito_identity_client.identity_pools = {
identity_pool_arn: IdentityPool(
id=identity_pool_id,
arn=identity_pool_arn,
region=AWS_REGION_US_EAST_1,
name=identity_pool_name,
associated_pools=[
{
"ProviderName": f"cognito-idp.{AWS_REGION_US_EAST_1}.amazonaws.com/eu-west-1_123456789"
}
],
roles=IdentityPoolRoles(
authenticated=authenticated_role,
),
)
}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIdentity",
cognito_identity_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_identity_client.cognito_identity_client",
cognito_identity_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_self_registration_disabled.cognito_user_pool_self_registration_disabled import (
cognito_user_pool_self_registration_disabled,
)
check = cognito_user_pool_self_registration_disabled()
result = check.execute()
assert len(result) == 1
assert result[0].status == "PASS"
assert result[0].status_extended == (
f"User pool {user_pool_name} has self registration disabled."
)
assert result[0].resource_id == user_pool_id
assert result[0].resource_arn == user_pool_arn
def test_cognito_identity_pools_allow_admin_create_user_disabled(self):
cognito_client = mock.MagicMock
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
user_pool_name = "eu-west-1_123456789"
user_pool_id = "eu-west-1_123456789"
cognito_client.user_pools = {
user_pool_arn: UserPool(
admin_create_user_config=AdminCreateUserConfig(
allow_admin_create_user_only=False
),
region=AWS_REGION_US_EAST_1,
id=user_pool_id,
arn=user_pool_arn,
name=user_pool_name,
last_modified=datetime.now(),
creation_date=datetime.now(),
status="ACTIVE",
)
}
cognito_identity_client = mock.MagicMock
identity_pool_name = "eu-west-1_123456789"
identity_pool_id = "eu-west-1_123456789"
identity_pool_arn = f"arn:aws:cognito-identity:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:identitypool/eu-west-1_123456789"
authenticated_role = "authenticated_role"
cognito_identity_client.identity_pools = {
identity_pool_arn: IdentityPool(
id=identity_pool_id,
arn=identity_pool_arn,
region=AWS_REGION_US_EAST_1,
name=identity_pool_name,
associated_pools=[
{
"ProviderName": f"cognito-idp.{AWS_REGION_US_EAST_1}.amazonaws.com/eu-west-1_123456789"
}
],
roles=IdentityPoolRoles(
authenticated=authenticated_role,
),
)
}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIdentity",
cognito_identity_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_identity_client.cognito_identity_client",
cognito_identity_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_self_registration_disabled.cognito_user_pool_self_registration_disabled import (
cognito_user_pool_self_registration_disabled,
)
check = cognito_user_pool_self_registration_disabled()
result = check.execute()
assert len(result) == 1
assert result[0].status == "FAIL"
assert result[0].status_extended == (
f"User pool {user_pool_name} has self registration enabled assuming the role(s): {identity_pool_name}({authenticated_role})."
)
assert result[0].resource_id == user_pool_id
assert result[0].resource_arn == user_pool_arn
@@ -0,0 +1,113 @@
from datetime import datetime
from unittest import mock
from prowler.providers.aws.services.cognito.cognito_service import (
PasswordPolicy,
UserPool,
)
from tests.providers.aws.utils import AWS_ACCOUNT_NUMBER, AWS_REGION_US_EAST_1
class Test_cognito_user_pool_temporary_password_expiration:
def test_cognito_no_user_pools(self):
cognito_client = mock.MagicMock
cognito_client.user_pools = {}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_temporary_password_expiration.cognito_user_pool_temporary_password_expiration import (
cognito_user_pool_temporary_password_expiration,
)
check = cognito_user_pool_temporary_password_expiration()
result = check.execute()
assert len(result) == 0
def test_cognito_user_pools_password_expiration_8(self):
cognito_client = mock.MagicMock
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
user_pool_id = "eu-west-1_123456789"
user_pool_name = "user_pool_name"
cognito_client.user_pools = {
user_pool_arn: UserPool(
password_policy=PasswordPolicy(
temporary_password_validity_days=8,
),
region=AWS_REGION_US_EAST_1,
id=user_pool_id,
arn=user_pool_arn,
name=user_pool_name,
last_modified=datetime.now(),
creation_date=datetime.now(),
status="ACTIVE",
)
}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_temporary_password_expiration.cognito_user_pool_temporary_password_expiration import (
cognito_user_pool_temporary_password_expiration,
)
check = cognito_user_pool_temporary_password_expiration()
result = check.execute()
assert len(result) == 1
assert result[0].status == "FAIL"
assert result[0].status_extended == (
f"User pool {user_pool_name} has temporary password expiration set to 8 days."
)
assert result[0].resource_id == user_pool_id
assert result[0].resource_arn == user_pool_arn
def test_cognito_user_pools_password_expiration_7(self):
cognito_client = mock.MagicMock
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
user_pool_name = "user_pool_name"
user_pool_id = "eu-west-1_123456789"
cognito_client.user_pools = {
user_pool_arn: UserPool(
password_policy=PasswordPolicy(
temporary_password_validity_days=7,
),
region=AWS_REGION_US_EAST_1,
id=user_pool_id,
arn=user_pool_arn,
name=user_pool_name,
last_modified=datetime.now(),
creation_date=datetime.now(),
status="ACTIVE",
)
}
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_temporary_password_expiration.cognito_user_pool_temporary_password_expiration import (
cognito_user_pool_temporary_password_expiration,
)
check = cognito_user_pool_temporary_password_expiration()
result = check.execute()
assert len(result) == 1
assert result[0].status == "PASS"
assert result[0].status_extended == (
f"User pool {user_pool_name} has temporary password expiration set to 7 days."
)
assert result[0].resource_id == user_pool_id
assert result[0].resource_arn == user_pool_arn
@@ -0,0 +1,146 @@
from datetime import datetime
from unittest import mock
from prowler.providers.aws.services.cognito.cognito_service import UserPool
from prowler.providers.aws.services.wafv2.wafv2_service import WebAclv2
from tests.providers.aws.utils import AWS_ACCOUNT_NUMBER, AWS_REGION_US_EAST_1
class Test_cognito_user_pool_waf_acl_attached:
def test_cognito_no_user_pools(self):
cognito_client = mock.MagicMock
cognito_client.user_pools = {}
cognito_client.audited_account = AWS_ACCOUNT_NUMBER
wafv2_client = mock.MagicMock
wafv2_client.web_acls = []
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.wafv2.wafv2_service.WAFv2",
new=wafv2_client,
), mock.patch(
"prowler.providers.aws.services.wafv2.wafv2_client.wafv2_client",
new=wafv2_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_waf_acl_attached.cognito_user_pool_waf_acl_attached import (
cognito_user_pool_waf_acl_attached,
)
check = cognito_user_pool_waf_acl_attached()
result = check.execute()
assert len(result) == 0
def test_cognito_no_web_acls(self):
cognito_client = mock.MagicMock
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
user_pool_id = "eu-west-1_123456789"
user_pool_name = "user_pool_name"
cognito_client.user_pools = {
user_pool_arn: UserPool(
region=AWS_REGION_US_EAST_1,
id=user_pool_id,
arn=user_pool_arn,
name=user_pool_name,
last_modified=datetime.now(),
creation_date=datetime.now(),
status="ACTIVE",
)
}
cognito_client.audited_account = AWS_ACCOUNT_NUMBER
wafv2_client = mock.MagicMock
wafv2_client.web_acls = []
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.wafv2.wafv2_service.WAFv2",
new=wafv2_client,
), mock.patch(
"prowler.providers.aws.services.wafv2.wafv2_client.wafv2_client",
new=wafv2_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_waf_acl_attached.cognito_user_pool_waf_acl_attached import (
cognito_user_pool_waf_acl_attached,
)
check = cognito_user_pool_waf_acl_attached()
result = check.execute()
assert len(result) == 1
assert result[0].status == "FAIL"
assert (
result[0].status_extended
== f"Cognito User Pool {user_pool_name} is not associated with a WAF Web ACL."
)
assert result[0].resource_id == user_pool_id
assert result[0].resource_arn == user_pool_arn
def test_cognito_with_web_acls(self):
cognito_client = mock.MagicMock
user_pool_arn = f"arn:aws:cognito-idp:{AWS_REGION_US_EAST_1}:{AWS_ACCOUNT_NUMBER}:userpool/eu-west-1_123456789"
user_pool_id = "eu-west-1_123456789"
user_pool_name = "user_pool_name"
cognito_client.user_pools = {
user_pool_arn: UserPool(
region=AWS_REGION_US_EAST_1,
id=user_pool_id,
arn=user_pool_arn,
name=user_pool_name,
last_modified=datetime.now(),
creation_date=datetime.now(),
status="ACTIVE",
)
}
cognito_client.audited_account = AWS_ACCOUNT_NUMBER
wafv2_client = mock.MagicMock
web_acl_arn = "arn:aws:wafv2:us-east-1:123456789012:regional/webacl/abcd1234"
web_acl_name = "abcd1234"
web_acl_id = "abcd1234"
wafv2_client.web_acls = [
WebAclv2(
arn=web_acl_arn,
name=web_acl_name,
id=web_acl_id,
albs=[],
user_pools=[user_pool_arn],
region="us-east-1",
)
]
with mock.patch(
"prowler.providers.aws.services.cognito.cognito_service.CognitoIDP",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.cognito.cognito_idp_client.cognito_idp_client",
new=cognito_client,
), mock.patch(
"prowler.providers.aws.services.wafv2.wafv2_service.WAFv2",
new=wafv2_client,
), mock.patch(
"prowler.providers.aws.services.wafv2.wafv2_client.wafv2_client",
new=wafv2_client,
):
from prowler.providers.aws.services.cognito.cognito_user_pool_waf_acl_attached.cognito_user_pool_waf_acl_attached import (
cognito_user_pool_waf_acl_attached,
)
check = cognito_user_pool_waf_acl_attached()
result = check.execute()
assert len(result) == 1
assert result[0].status == "PASS"
assert (
result[0].status_extended
== f"Cognito User Pool {user_pool_name} is associated with the WAF Web ACL {web_acl_name}."
)
assert result[0].resource_id == user_pool_id
assert result[0].resource_arn == user_pool_arn
@@ -101,3 +101,28 @@ class Test_WAFv2_Service:
assert len(wafv2.web_acls) == 1
assert len(wafv2.web_acls[0].albs) == 1
assert lb["LoadBalancerArn"] in wafv2.web_acls[0].albs
# Test WAFv2 describe Web user pools
@mock_aws
def test__list_resources_for_web_user_pools__(self):
wafv2 = client("wafv2", region_name=AWS_REGION_EU_WEST_1)
cognito = client("cognito-idp", region_name=AWS_REGION_EU_WEST_1)
waf = wafv2.create_web_acl(
Scope="REGIONAL",
Name="my-web-acl",
DefaultAction={"Allow": {}},
VisibilityConfig={
"SampledRequestsEnabled": False,
"CloudWatchMetricsEnabled": False,
"MetricName": "idk",
},
)["Summary"]
user_pool = cognito.create_user_pool(PoolName="my-user-pool")["UserPool"]
wafv2.associate_web_acl(WebACLArn=waf["ARN"], ResourceArn=user_pool["Arn"])
# WAFv2 client for this test class
aws = set_mocked_aws_provider([AWS_REGION_EU_WEST_1])
wafv2 = WAFv2(aws)
wafv2.web_acls[0].user_pools.append(user_pool["Arn"])
assert len(wafv2.web_acls) == 1
assert len(wafv2.web_acls[0].user_pools) == 1
assert user_pool["Arn"] in wafv2.web_acls[0].user_pools
@@ -38,6 +38,7 @@ class Test_wafv2_webacl_logging_enabled:
name=waf_name,
id=waf_id,
albs=[],
user_pools=[],
region=AWS_REGION_EU_WEST_1,
logging_enabled=True,
)
@@ -75,6 +76,7 @@ class Test_wafv2_webacl_logging_enabled:
name=waf_name,
id=waf_id,
albs=[],
user_pools=[],
region=AWS_REGION_EU_WEST_1,
logging_enabled=False,
)