fix(network): correct what the outbound guard logs

This commit is contained in:
pedrooot committed 2026-10-08 00:12:26 +02:00
1 parent e5ebf25c82
commit 2829a7368c
2 files changed
+23 -1

No files matched your search

+6 -1
View File
@@ -117,7 +117,9 @@ def extract_host(url: str) -> str:
return scp_like.group("host")
host = urlparse(url).hostname
if not host:
raise OutboundURLNotAllowedError(f"Could not read a host from URL {url!r}")
# The URL itself stays out of the message: a configured repository or auth
# URL can carry credentials in its userinfo, and this message is logged
raise OutboundURLNotAllowedError("Could not read a host from the supplied URL")
return host
@@ -128,6 +130,9 @@ def validate_outbound_host(host: str) -> None:
hostile DNS server can still answer differently the second time.
"""
if outbound_check_skipped():
logger.warning(
f"{SKIP_OUTBOUND_CHECK_ENV} is set — destination check disabled for host {host!r}"
)
return
networks = allowed_private_networks()
+17
View File
@@ -109,6 +109,15 @@ class TestOutboundCheckOptOut:
with pytest.raises(OutboundURLNotAllowedError):
validate_outbound_host("169.254.169.254")
def test_logs_the_skip_so_an_operator_sees_the_disabled_control(self, monkeypatch):
monkeypatch.setenv(SKIP_OUTBOUND_CHECK_ENV, "true")
with mock.patch("prowler.lib.network.ssrf.logger") as logged:
validate_outbound_host("169.254.169.254")
assert logged.warning.call_count == 1
assert SKIP_OUTBOUND_CHECK_ENV in logged.warning.call_args.args[0]
def test_the_cli_entrypoint_opts_out(self, monkeypatch):
"""prowler() must set the opt-out before it does anything else."""
# a throwaway mapping, so the variable prowler() sets cannot leak into
@@ -218,6 +227,14 @@ class TestExtractHost:
with pytest.raises(OutboundURLNotAllowedError, match="Could not read a host"):
extract_host("not a url")
def test_keeps_the_url_out_of_the_rejection_message(self):
# the message is logged, and a configured URL can carry credentials
with pytest.raises(OutboundURLNotAllowedError) as rejection:
extract_host("https://user:s3cr3t@/org/repo.git")
assert "s3cr3t" not in str(rejection.value)
assert "user" not in str(rejection.value)
class TestValidateOutboundURL:
def test_rejects_a_disallowed_scheme(self):