feat(app): Add new Azure functions checks (#4189)

Co-authored-by: Sergio <sergio@prowler.com>
This commit is contained in:
Rubén De la Torre Vico
2024-06-21 11:32:31 -04:00
committed by GitHub
co-authored by Sergio
parent 465261e1df
commit 536f0df9d3
38 changed files with 2090 additions and 42 deletions
@@ -0,0 +1,147 @@
from unittest import mock
from uuid import uuid4
from tests.providers.azure.azure_fixtures import (
AZURE_SUBSCRIPTION_ID,
set_mocked_azure_provider,
)
class Test_app_function_access_keys_configured:
def test_app_no_subscriptions(self):
app_client = mock.MagicMock
with mock.patch(
"prowler.providers.common.provider.Provider.get_global_provider",
return_value=set_mocked_azure_provider(),
), mock.patch(
"prowler.providers.azure.services.app.app_function_access_keys_configured.app_function_access_keys_configured.app_client",
new=app_client,
):
from prowler.providers.azure.services.app.app_function_access_keys_configured.app_function_access_keys_configured import (
app_function_access_keys_configured,
)
app_client.functions = {}
check = app_function_access_keys_configured()
result = check.execute()
assert len(result) == 0
def test_app_subscription_empty(self):
app_client = mock.MagicMock
app_client.functions = {AZURE_SUBSCRIPTION_ID: {}}
with mock.patch(
"prowler.providers.common.provider.Provider.get_global_provider",
return_value=set_mocked_azure_provider(),
), mock.patch(
"prowler.providers.azure.services.app.app_function_access_keys_configured.app_function_access_keys_configured.app_client",
new=app_client,
):
from prowler.providers.azure.services.app.app_function_access_keys_configured.app_function_access_keys_configured import (
app_function_access_keys_configured,
)
check = app_function_access_keys_configured()
result = check.execute()
assert len(result) == 0
def test_app_function_no_keys(self):
app_client = mock.MagicMock
app_client.functions = {AZURE_SUBSCRIPTION_ID: {}}
with mock.patch(
"prowler.providers.common.provider.Provider.get_global_provider",
return_value=set_mocked_azure_provider(),
), mock.patch(
"prowler.providers.azure.services.app.app_function_access_keys_configured.app_function_access_keys_configured.app_client",
new=app_client,
):
from prowler.providers.azure.services.app.app_function_access_keys_configured.app_function_access_keys_configured import (
app_function_access_keys_configured,
)
from prowler.providers.azure.services.app.app_service import FunctionApp
function_id = str(uuid4())
app_client.functions = {
AZURE_SUBSCRIPTION_ID: {
function_id: FunctionApp(
name="function1",
location="West Europe",
kind="functionapp,linux",
function_keys={},
enviroment_variables={},
identity=None,
public_access=False,
vnet_subnet_id=None,
ftps_state="AllAllowed",
)
}
}
check = app_function_access_keys_configured()
result = check.execute()
assert len(result) == 1
assert result[0].status == "FAIL"
assert (
result[0].status_extended
== "Function function1 does not have function keys configured."
)
assert result[0].resource_id == function_id
assert result[0].resource_name == "function1"
assert result[0].subscription == AZURE_SUBSCRIPTION_ID
assert result[0].location == "West Europe"
def test_app_function_using_functions_keys(self):
app_client = mock.MagicMock
app_client.functions = {AZURE_SUBSCRIPTION_ID: {}}
with mock.patch(
"prowler.providers.common.provider.Provider.get_global_provider",
return_value=set_mocked_azure_provider(),
), mock.patch(
"prowler.providers.azure.services.app.app_function_access_keys_configured.app_function_access_keys_configured.app_client",
new=app_client,
):
from prowler.providers.azure.services.app.app_function_access_keys_configured.app_function_access_keys_configured import (
app_function_access_keys_configured,
)
from prowler.providers.azure.services.app.app_service import FunctionApp
function_id = str(uuid4())
app_client.functions = {
AZURE_SUBSCRIPTION_ID: {
function_id: FunctionApp(
name="function1",
location="West Europe",
kind="functionapp,linux",
function_keys={
"default": "key1",
"key2": "key2",
},
enviroment_variables={},
identity=None,
public_access=False,
vnet_subnet_id=None,
ftps_state="AllAllowed",
)
}
}
check = app_function_access_keys_configured()
result = check.execute()
assert len(result) == 1
assert result[0].status == "PASS"
assert (
result[0].status_extended
== "Function function1 has function keys configured."
)
assert result[0].resource_id == function_id
assert result[0].resource_name == "function1"
assert result[0].subscription == AZURE_SUBSCRIPTION_ID
assert result[0].location == "West Europe"
@@ -0,0 +1,305 @@
from unittest import mock
from uuid import uuid4
from tests.providers.azure.azure_fixtures import (
AZURE_SUBSCRIPTION_ID,
set_mocked_azure_provider,
)
class Test_app_function_application_insights_enabled:
def test_app_no_subscriptions(self):
app_client = mock.MagicMock
with mock.patch(
"prowler.providers.common.provider.Provider.get_global_provider",
return_value=set_mocked_azure_provider(),
), mock.patch(
"prowler.providers.azure.services.app.app_function_application_insights_enabled.app_function_application_insights_enabled.app_client",
new=app_client,
):
from prowler.providers.azure.services.app.app_function_application_insights_enabled.app_function_application_insights_enabled import (
app_function_application_insights_enabled,
)
app_client.functions = {}
check = app_function_application_insights_enabled()
result = check.execute()
assert len(result) == 0
def test_app_subscription_empty(self):
app_client = mock.MagicMock
with mock.patch(
"prowler.providers.common.provider.Provider.get_global_provider",
return_value=set_mocked_azure_provider(),
), mock.patch(
"prowler.providers.azure.services.app.app_function_application_insights_enabled.app_function_application_insights_enabled.app_client",
new=app_client,
):
from prowler.providers.azure.services.app.app_function_application_insights_enabled.app_function_application_insights_enabled import (
app_function_application_insights_enabled,
)
app_client.functions = {AZURE_SUBSCRIPTION_ID: {}}
check = app_function_application_insights_enabled()
result = check.execute()
assert len(result) == 0
def test_app_function_no_app_insights(self):
app_client = mock.MagicMock
app_insights = mock.MagicMock
with mock.patch(
"prowler.providers.common.provider.Provider.get_global_provider",
return_value=set_mocked_azure_provider(),
), mock.patch(
"prowler.providers.azure.services.app.app_function_application_insights_enabled.app_function_application_insights_enabled.app_client",
new=app_client,
), mock.patch(
"prowler.providers.azure.services.app.app_function_application_insights_enabled.app_function_application_insights_enabled.appinsights_client",
new=app_insights,
):
from prowler.providers.azure.services.app.app_function_application_insights_enabled.app_function_application_insights_enabled import (
app_function_application_insights_enabled,
)
from prowler.providers.azure.services.app.app_service import FunctionApp
from prowler.providers.azure.services.appinsights.appinsights_service import (
Component,
)
function_id = str(uuid4())
app_client.functions = {
AZURE_SUBSCRIPTION_ID: {
function_id: FunctionApp(
name="function1",
location="West Europe",
kind="functionapp,linux",
function_keys={},
enviroment_variables={},
identity=None,
public_access=False,
vnet_subnet_id=None,
ftps_state="AllAllowed",
)
}
}
app_insights.components = {
AZURE_SUBSCRIPTION_ID: {
"app_id-1": Component(
resource_id="component_id",
resource_name="component_name",
location="West Europe",
instrumentation_key="1234",
)
}
}
check = app_function_application_insights_enabled()
result = check.execute()
assert len(result) == 1
assert result[0].status == "FAIL"
assert (
result[0].status_extended
== "Function function1 is not using Application Insights."
)
assert result[0].resource_id == function_id
assert result[0].resource_name == "function1"
assert result[0].subscription == AZURE_SUBSCRIPTION_ID
assert result[0].location == "West Europe"
def test_app_function_using_app_insights(self):
app_client = mock.MagicMock
app_insights = mock.MagicMock
with mock.patch(
"prowler.providers.common.provider.Provider.get_global_provider",
return_value=set_mocked_azure_provider(),
), mock.patch(
"prowler.providers.azure.services.app.app_function_application_insights_enabled.app_function_application_insights_enabled.app_client",
new=app_client,
), mock.patch(
"prowler.providers.azure.services.app.app_function_application_insights_enabled.app_function_application_insights_enabled.appinsights_client",
new=app_insights,
):
from prowler.providers.azure.services.app.app_function_application_insights_enabled.app_function_application_insights_enabled import (
app_function_application_insights_enabled,
)
from prowler.providers.azure.services.app.app_service import FunctionApp
from prowler.providers.azure.services.appinsights.appinsights_service import (
Component,
)
function_id = str(uuid4())
app_client.functions = {
AZURE_SUBSCRIPTION_ID: {
function_id: FunctionApp(
name="function1",
location="West Europe",
kind="functionapp,linux",
function_keys={},
enviroment_variables={"APPINSIGHTS_INSTRUMENTATIONKEY": "1234"},
identity=None,
public_access=False,
vnet_subnet_id=None,
ftps_state="AllAllowed",
)
}
}
app_insights.components = {
AZURE_SUBSCRIPTION_ID: {
"app_id-1": Component(
resource_id="component_id",
resource_name="component_name",
location="West Europe",
instrumentation_key="1234",
)
}
}
check = app_function_application_insights_enabled()
result = check.execute()
assert len(result) == 1
assert result[0].status == "PASS"
assert (
result[0].status_extended
== "Function function1 is using Application Insights."
)
assert result[0].resource_id == function_id
assert result[0].resource_name == "function1"
assert result[0].subscription == AZURE_SUBSCRIPTION_ID
assert result[0].location == "West Europe"
def test_app_function_using_app_insights_different_key(self):
app_client = mock.MagicMock
app_insights = mock.MagicMock
with mock.patch(
"prowler.providers.common.provider.Provider.get_global_provider",
return_value=set_mocked_azure_provider(),
), mock.patch(
"prowler.providers.azure.services.app.app_function_application_insights_enabled.app_function_application_insights_enabled.app_client",
new=app_client,
), mock.patch(
"prowler.providers.azure.services.app.app_function_application_insights_enabled.app_function_application_insights_enabled.appinsights_client",
new=app_insights,
):
from prowler.providers.azure.services.app.app_function_application_insights_enabled.app_function_application_insights_enabled import (
app_function_application_insights_enabled,
)
from prowler.providers.azure.services.app.app_service import FunctionApp
from prowler.providers.azure.services.appinsights.appinsights_service import (
Component,
)
function_id = str(uuid4())
app_client.functions = {
AZURE_SUBSCRIPTION_ID: {
function_id: FunctionApp(
name="function1",
location="West Europe",
kind="functionapp,linux",
function_keys={},
enviroment_variables={"APPINSIGHTS_INSTRUMENTATIONKEY": "1234"},
identity=None,
public_access=False,
vnet_subnet_id=None,
ftps_state="AllAllowed",
)
}
}
app_insights.components = {
AZURE_SUBSCRIPTION_ID: {
"app_id-1": Component(
resource_id="component_id",
resource_name="component_name",
location="West Europe",
instrumentation_key="5678",
)
}
}
check = app_function_application_insights_enabled()
result = check.execute()
assert len(result) == 1
assert result[0].status == "FAIL"
assert (
result[0].status_extended
== "Function function1 is not using Application Insights."
)
assert result[0].resource_id == function_id
assert result[0].resource_name == "function1"
assert result[0].subscription == AZURE_SUBSCRIPTION_ID
assert result[0].location == "West Europe"
def test_app_function_with_app_insights_no_key(self):
app_client = mock.MagicMock
app_insights = mock.MagicMock
with mock.patch(
"prowler.providers.common.provider.Provider.get_global_provider",
return_value=set_mocked_azure_provider(),
), mock.patch(
"prowler.providers.azure.services.app.app_function_application_insights_enabled.app_function_application_insights_enabled.app_client",
new=app_client,
), mock.patch(
"prowler.providers.azure.services.app.app_function_application_insights_enabled.app_function_application_insights_enabled.appinsights_client",
new=app_insights,
):
from prowler.providers.azure.services.app.app_function_application_insights_enabled.app_function_application_insights_enabled import (
app_function_application_insights_enabled,
)
from prowler.providers.azure.services.app.app_service import FunctionApp
from prowler.providers.azure.services.appinsights.appinsights_service import (
Component,
)
function_id = str(uuid4())
app_client.functions = {
AZURE_SUBSCRIPTION_ID: {
function_id: FunctionApp(
name="function1",
location="West Europe",
kind="functionapp,linux",
function_keys={},
enviroment_variables={},
identity=None,
public_access=False,
vnet_subnet_id=None,
ftps_state="AllAllowed",
)
}
}
app_insights.components = {
AZURE_SUBSCRIPTION_ID: {
"app_id-1": Component(
resource_id="component_id",
resource_name="component_name",
location="West Europe",
instrumentation_key="Not Found",
)
}
}
check = app_function_application_insights_enabled()
result = check.execute()
assert len(result) == 1
assert result[0].status == "FAIL"
assert (
result[0].status_extended
== "Function function1 is not using Application Insights."
)
assert result[0].resource_id == function_id
assert result[0].resource_name == "function1"
assert result[0].subscription == AZURE_SUBSCRIPTION_ID
assert result[0].location == "West Europe"
@@ -0,0 +1,187 @@
from unittest import mock
from uuid import uuid4
from tests.providers.azure.azure_fixtures import (
AZURE_SUBSCRIPTION_ID,
set_mocked_azure_provider,
)
class Test_app_function_ftps_deployment_disabled:
def test_no_subscriptions(self):
app_client = mock.MagicMock
with mock.patch(
"prowler.providers.common.provider.Provider.get_global_provider",
return_value=set_mocked_azure_provider(),
), mock.patch(
"prowler.providers.azure.services.app.app_function_ftps_deployment_disabled.app_function_ftps_deployment_disabled.app_client",
new=app_client,
):
from prowler.providers.azure.services.app.app_function_ftps_deployment_disabled.app_function_ftps_deployment_disabled import (
app_function_ftps_deployment_disabled,
)
app_client.functions = {}
check = app_function_ftps_deployment_disabled()
result = check.execute()
assert len(result) == 0
def test_subscription_empty(self):
app_client = mock.MagicMock
with mock.patch(
"prowler.providers.common.provider.Provider.get_global_provider",
return_value=set_mocked_azure_provider(),
), mock.patch(
"prowler.providers.azure.services.app.app_function_ftps_deployment_disabled.app_function_ftps_deployment_disabled.app_client",
new=app_client,
):
from prowler.providers.azure.services.app.app_function_ftps_deployment_disabled.app_function_ftps_deployment_disabled import (
app_function_ftps_deployment_disabled,
)
app_client.functions = {AZURE_SUBSCRIPTION_ID: {}}
check = app_function_ftps_deployment_disabled()
result = check.execute()
assert len(result) == 0
def test_function_ftp_deployment_enabled(self):
app_client = mock.MagicMock
with mock.patch(
"prowler.providers.common.provider.Provider.get_global_provider",
return_value=set_mocked_azure_provider(),
), mock.patch(
"prowler.providers.azure.services.app.app_function_ftps_deployment_disabled.app_function_ftps_deployment_disabled.app_client",
new=app_client,
):
from prowler.providers.azure.services.app.app_function_ftps_deployment_disabled.app_function_ftps_deployment_disabled import (
app_function_ftps_deployment_disabled,
)
from prowler.providers.azure.services.app.app_service import FunctionApp
function_id = str(uuid4())
app_client.functions = {
AZURE_SUBSCRIPTION_ID: {
function_id: FunctionApp(
name="function1",
location="West Europe",
kind="functionapp,linux",
function_keys={},
enviroment_variables={},
identity=mock.MagicMock(type="SystemAssigned"),
public_access=False,
vnet_subnet_id=None,
ftps_state="AllAllowed",
)
}
}
check = app_function_ftps_deployment_disabled()
result = check.execute()
assert len(result) == 1
assert result[0].status == "FAIL"
assert (
result[0].status_extended
== "Function function1 has FTP deployment enabled"
)
assert result[0].resource_name == "function1"
assert result[0].resource_id == function_id
assert result[0].location == "West Europe"
assert result[0].subscription == AZURE_SUBSCRIPTION_ID
def test_function_ftps_deployment_enabled(self):
app_client = mock.MagicMock
with mock.patch(
"prowler.providers.common.provider.Provider.get_global_provider",
return_value=set_mocked_azure_provider(),
), mock.patch(
"prowler.providers.azure.services.app.app_function_ftps_deployment_disabled.app_function_ftps_deployment_disabled.app_client",
new=app_client,
):
from prowler.providers.azure.services.app.app_function_ftps_deployment_disabled.app_function_ftps_deployment_disabled import (
app_function_ftps_deployment_disabled,
)
from prowler.providers.azure.services.app.app_service import FunctionApp
function_id = str(uuid4())
app_client.functions = {
AZURE_SUBSCRIPTION_ID: {
function_id: FunctionApp(
name="function1",
location="West Europe",
kind="functionapp,linux",
function_keys={},
enviroment_variables={},
identity=mock.MagicMock(type="SystemAssigned"),
public_access=False,
vnet_subnet_id=None,
ftps_state="FtpsOnly",
)
}
}
check = app_function_ftps_deployment_disabled()
result = check.execute()
assert len(result) == 1
assert result[0].status == "FAIL"
assert (
result[0].status_extended
== "Function function1 has FTPS deployment enabled"
)
assert result[0].resource_name == "function1"
assert result[0].resource_id == function_id
assert result[0].location == "West Europe"
assert result[0].subscription == AZURE_SUBSCRIPTION_ID
def test_function_ftp_and_ftps_deployment_disabled(self):
app_client = mock.MagicMock
with mock.patch(
"prowler.providers.common.provider.Provider.get_global_provider",
return_value=set_mocked_azure_provider(),
), mock.patch(
"prowler.providers.azure.services.app.app_function_ftps_deployment_disabled.app_function_ftps_deployment_disabled.app_client",
new=app_client,
):
from prowler.providers.azure.services.app.app_function_ftps_deployment_disabled.app_function_ftps_deployment_disabled import (
app_function_ftps_deployment_disabled,
)
from prowler.providers.azure.services.app.app_service import FunctionApp
function_id = str(uuid4())
app_client.functions = {
AZURE_SUBSCRIPTION_ID: {
function_id: FunctionApp(
name="function1",
location="West Europe",
kind="functionapp,linux",
function_keys={},
enviroment_variables={},
identity=mock.MagicMock(type="SystemAssigned"),
public_access=False,
vnet_subnet_id=None,
ftps_state="Disabled",
)
}
}
check = app_function_ftps_deployment_disabled()
result = check.execute()
assert len(result) == 1
assert result[0].status == "PASS"
assert (
result[0].status_extended
== "Function function1 has FTP and FTPS deployment disabled"
)
assert result[0].resource_name == "function1"
assert result[0].resource_id == function_id
assert result[0].location == "West Europe"
assert result[0].subscription == AZURE_SUBSCRIPTION_ID
@@ -0,0 +1,141 @@
from unittest import mock
from uuid import uuid4
from tests.providers.azure.azure_fixtures import (
AZURE_SUBSCRIPTION_ID,
set_mocked_azure_provider,
)
class Test_app_function_identity_is_configured:
def test_app_no_subscriptions(self):
app_client = mock.MagicMock
with mock.patch(
"prowler.providers.common.provider.Provider.get_global_provider",
return_value=set_mocked_azure_provider(),
), mock.patch(
"prowler.providers.azure.services.app.app_function_identity_is_configured.app_function_identity_is_configured.app_client",
new=app_client,
):
from prowler.providers.azure.services.app.app_function_identity_is_configured.app_function_identity_is_configured import (
app_function_identity_is_configured,
)
app_client.functions = {}
check = app_function_identity_is_configured()
result = check.execute()
assert len(result) == 0
def test_app_subscription_empty(self):
app_client = mock.MagicMock
with mock.patch(
"prowler.providers.common.provider.Provider.get_global_provider",
return_value=set_mocked_azure_provider(),
), mock.patch(
"prowler.providers.azure.services.app.app_function_identity_is_configured.app_function_identity_is_configured.app_client",
new=app_client,
):
from prowler.providers.azure.services.app.app_function_identity_is_configured.app_function_identity_is_configured import (
app_function_identity_is_configured,
)
app_client.functions = {AZURE_SUBSCRIPTION_ID: {}}
check = app_function_identity_is_configured()
result = check.execute()
assert len(result) == 0
def test_app_function_no_identity(self):
app_client = mock.MagicMock
with mock.patch(
"prowler.providers.common.provider.Provider.get_global_provider",
return_value=set_mocked_azure_provider(),
), mock.patch(
"prowler.providers.azure.services.app.app_function_identity_is_configured.app_function_identity_is_configured.app_client",
new=app_client,
):
from prowler.providers.azure.services.app.app_function_identity_is_configured.app_function_identity_is_configured import (
app_function_identity_is_configured,
)
from prowler.providers.azure.services.app.app_service import FunctionApp
function_id = str(uuid4())
app_client.functions = {
AZURE_SUBSCRIPTION_ID: {
function_id: FunctionApp(
name="function1",
location="West Europe",
kind="functionapp,linux",
function_keys={},
enviroment_variables={},
identity=None,
public_access=False,
vnet_subnet_id=None,
ftps_state="AllAllowed",
)
}
}
check = app_function_identity_is_configured()
result = check.execute()
assert len(result) == 1
assert result[0].status == "FAIL"
assert (
result[0].status_extended
== "Function function1 does not have a managed identity enabled."
)
assert result[0].resource_name == "function1"
assert result[0].resource_id == function_id
assert result[0].subscription == AZURE_SUBSCRIPTION_ID
assert result[0].location == "West Europe"
def test_app_function_identity_configured(self):
app_client = mock.MagicMock
with mock.patch(
"prowler.providers.common.provider.Provider.get_global_provider",
return_value=set_mocked_azure_provider(),
), mock.patch(
"prowler.providers.azure.services.app.app_function_identity_is_configured.app_function_identity_is_configured.app_client",
new=app_client,
):
from prowler.providers.azure.services.app.app_function_identity_is_configured.app_function_identity_is_configured import (
app_function_identity_is_configured,
)
from prowler.providers.azure.services.app.app_service import FunctionApp
function_id = str(uuid4())
app_client.functions = {
AZURE_SUBSCRIPTION_ID: {
function_id: FunctionApp(
name="function1",
location="West Europe",
kind="functionapp,linux",
function_keys={},
enviroment_variables={},
identity=mock.MagicMock(type="SystemAssigned"),
public_access=False,
vnet_subnet_id=None,
ftps_state="AllAllowed",
)
}
}
check = app_function_identity_is_configured()
result = check.execute()
assert len(result) == 1
assert result[0].status == "PASS"
assert (
result[0].status_extended
== "Function function1 has a SystemAssigned identity enabled."
)
assert result[0].resource_name == "function1"
assert result[0].resource_id == function_id
assert result[0].subscription == AZURE_SUBSCRIPTION_ID
assert result[0].location == "West Europe"
@@ -0,0 +1,239 @@
from unittest import mock
from uuid import uuid4
from prowler.providers.azure.config import USER_ACCESS_ADMINISTRATOR_ROLE_ID
from tests.providers.azure.azure_fixtures import (
AZURE_SUBSCRIPTION_ID,
set_mocked_azure_provider,
)
class Test_app_function_identity_without_admin_privileges:
def test_app_no_subscriptions(self):
app_client = mock.MagicMock
with mock.patch(
"prowler.providers.common.provider.Provider.get_global_provider",
return_value=set_mocked_azure_provider(),
), mock.patch(
"prowler.providers.azure.services.app.app_function_identity_without_admin_privileges.app_function_identity_without_admin_privileges.app_client",
new=app_client,
):
from prowler.providers.azure.services.app.app_function_identity_without_admin_privileges.app_function_identity_without_admin_privileges import (
app_function_identity_without_admin_privileges,
)
app_client.functions = {}
check = app_function_identity_without_admin_privileges()
result = check.execute()
assert len(result) == 0
def test_app_subscription_empty(self):
app_client = mock.MagicMock
with mock.patch(
"prowler.providers.common.provider.Provider.get_global_provider",
return_value=set_mocked_azure_provider(),
), mock.patch(
"prowler.providers.azure.services.app.app_function_identity_without_admin_privileges.app_function_identity_without_admin_privileges.app_client",
new=app_client,
):
from prowler.providers.azure.services.app.app_function_identity_without_admin_privileges.app_function_identity_without_admin_privileges import (
app_function_identity_without_admin_privileges,
)
app_client.functions = {AZURE_SUBSCRIPTION_ID: {}}
check = app_function_identity_without_admin_privileges()
result = check.execute()
assert len(result) == 0
def test_app_function_no_identity(self):
app_client = mock.MagicMock
with mock.patch(
"prowler.providers.common.provider.Provider.get_global_provider",
return_value=set_mocked_azure_provider(),
), mock.patch(
"prowler.providers.azure.services.app.app_function_identity_without_admin_privileges.app_function_identity_without_admin_privileges.app_client",
new=app_client,
):
from prowler.providers.azure.services.app.app_function_identity_without_admin_privileges.app_function_identity_without_admin_privileges import (
app_function_identity_without_admin_privileges,
)
from prowler.providers.azure.services.app.app_service import FunctionApp
function_id = str(uuid4())
app_client.functions = {
AZURE_SUBSCRIPTION_ID: {
function_id: FunctionApp(
name="function1",
location="West Europe",
kind="functionapp,linux",
function_keys={},
enviroment_variables={},
identity=None,
public_access=False,
vnet_subnet_id=None,
ftps_state="AllAllowed",
)
}
}
check = app_function_identity_without_admin_privileges()
result = check.execute()
assert len(result) == 0
def test_app_function_no_admin_roles(self):
app_client = mock.MagicMock
iam_client = mock.MagicMock
with mock.patch(
"prowler.providers.common.provider.Provider.get_global_provider",
return_value=set_mocked_azure_provider(),
), mock.patch(
"prowler.providers.azure.services.app.app_function_identity_without_admin_privileges.app_function_identity_without_admin_privileges.app_client",
new=app_client,
), mock.patch(
"prowler.providers.azure.services.app.app_function_identity_without_admin_privileges.app_function_identity_without_admin_privileges.iam_client",
new=iam_client,
):
from prowler.providers.azure.services.app.app_function_identity_without_admin_privileges.app_function_identity_without_admin_privileges import (
app_function_identity_without_admin_privileges,
)
from prowler.providers.azure.services.app.app_service import FunctionApp
from prowler.providers.azure.services.iam.iam_service import (
Role,
RoleAssignment,
)
function_id = str(uuid4())
app_client.functions = {
AZURE_SUBSCRIPTION_ID: {
function_id: FunctionApp(
name="function1",
location="West Europe",
kind="functionapp,linux",
function_keys={},
enviroment_variables={},
identity=mock.MagicMock(principal_id="123"),
public_access=False,
vnet_subnet_id=None,
ftps_state="AllAllowed",
)
}
}
iam_client.role_assignments = {
AZURE_SUBSCRIPTION_ID: {
"1": RoleAssignment(
role_id="1",
agent_id="123",
agent_type="User",
)
}
}
iam_client.roles = {
AZURE_SUBSCRIPTION_ID: [
Role(
id="1",
name="role1",
type="User",
assignable_scopes=[],
permissions=[],
)
]
}
check = app_function_identity_without_admin_privileges()
result = check.execute()
assert len(result) == 1
assert result[0].status == "PASS"
assert (
result[0].status_extended
== "Function function1 has a managed identity enabled but without admin privileges."
)
assert result[0].resource_id == function_id
assert result[0].resource_name == "function1"
assert result[0].subscription == AZURE_SUBSCRIPTION_ID
assert result[0].location == "West Europe"
def test_app_function_admin_roles(self):
app_client = mock.MagicMock
iam_client = mock.MagicMock
with mock.patch(
"prowler.providers.common.provider.Provider.get_global_provider",
return_value=set_mocked_azure_provider(),
), mock.patch(
"prowler.providers.azure.services.app.app_function_identity_without_admin_privileges.app_function_identity_without_admin_privileges.app_client",
new=app_client,
), mock.patch(
"prowler.providers.azure.services.app.app_function_identity_without_admin_privileges.app_function_identity_without_admin_privileges.iam_client",
new=iam_client,
):
from prowler.providers.azure.services.app.app_function_identity_without_admin_privileges.app_function_identity_without_admin_privileges import (
app_function_identity_without_admin_privileges,
)
from prowler.providers.azure.services.app.app_service import FunctionApp
from prowler.providers.azure.services.iam.iam_service import (
Role,
RoleAssignment,
)
function_id = str(uuid4())
app_client.functions = {
AZURE_SUBSCRIPTION_ID: {
function_id: FunctionApp(
name="function1",
location="West Europe",
kind="functionapp,linux",
function_keys={},
enviroment_variables={},
identity=mock.MagicMock(principal_id="123"),
public_access=False,
vnet_subnet_id=None,
ftps_state="AllAllowed",
)
}
}
iam_client.role_assignments = {
AZURE_SUBSCRIPTION_ID: {
"1": RoleAssignment(
role_id=USER_ACCESS_ADMINISTRATOR_ROLE_ID,
agent_id="123",
agent_type="User",
)
}
}
iam_client.roles = {
AZURE_SUBSCRIPTION_ID: [
Role(
id=USER_ACCESS_ADMINISTRATOR_ROLE_ID,
name="User Access Administrator",
type="User",
assignable_scopes=[],
permissions=[],
)
]
}
check = app_function_identity_without_admin_privileges()
result = check.execute()
assert len(result) == 1
assert result[0].status == "FAIL"
assert (
result[0].status_extended
== "Function function1 has a managed identity enabled and it is configure with admin privileges using role User Access Administrator."
)
assert result[0].resource_id == function_id
assert result[0].resource_name == "function1"
assert result[0].subscription == AZURE_SUBSCRIPTION_ID
assert result[0].location == "West Europe"
@@ -0,0 +1,139 @@
from unittest import mock
from uuid import uuid4
from tests.providers.azure.azure_fixtures import (
AZURE_SUBSCRIPTION_ID,
set_mocked_azure_provider,
)
class Test_app_function_latest_runtime_version:
def test_app_no_subscriptions(self):
app_client = mock.MagicMock
with mock.patch(
"prowler.providers.common.provider.Provider.get_global_provider",
return_value=set_mocked_azure_provider(),
), mock.patch(
"prowler.providers.azure.services.app.app_function_latest_runtime_version.app_function_latest_runtime_version.app_client",
new=app_client,
):
from prowler.providers.azure.services.app.app_function_latest_runtime_version.app_function_latest_runtime_version import (
app_function_latest_runtime_version,
)
app_client.functions = {}
check = app_function_latest_runtime_version()
result = check.execute()
assert len(result) == 0
def test_app_subscription_empty(self):
app_client = mock.MagicMock
with mock.patch(
"prowler.providers.common.provider.Provider.get_global_provider",
return_value=set_mocked_azure_provider(),
), mock.patch(
"prowler.providers.azure.services.app.app_function_latest_runtime_version.app_function_latest_runtime_version.app_client",
new=app_client,
):
from prowler.providers.azure.services.app.app_function_latest_runtime_version.app_function_latest_runtime_version import (
app_function_latest_runtime_version,
)
app_client.functions = {AZURE_SUBSCRIPTION_ID: {}}
check = app_function_latest_runtime_version()
result = check.execute()
assert len(result) == 0
def test_app_function_runtime_is_latest(self):
app_client = mock.MagicMock
with mock.patch(
"prowler.providers.common.provider.Provider.get_global_provider",
return_value=set_mocked_azure_provider(),
), mock.patch(
"prowler.providers.azure.services.app.app_function_latest_runtime_version.app_function_latest_runtime_version.app_client",
new=app_client,
):
from prowler.providers.azure.services.app.app_function_latest_runtime_version.app_function_latest_runtime_version import (
app_function_latest_runtime_version,
)
from prowler.providers.azure.services.app.app_service import FunctionApp
function_id = str(uuid4())
app_client.functions = {
AZURE_SUBSCRIPTION_ID: {
function_id: FunctionApp(
name="function1",
location="West Europe",
kind="functionapp,linux",
function_keys={},
enviroment_variables={"FUNCTIONS_EXTENSION_VERSION": "~4"},
identity=None,
public_access=False,
vnet_subnet_id=None,
ftps_state="AllAllowed",
)
}
}
check = app_function_latest_runtime_version()
result = check.execute()
assert len(result) == 1
assert result[0].status == "PASS"
assert result[0].status_extended == (
"Function function1 is using the latest runtime."
)
assert result[0].resource_id == function_id
assert result[0].resource_name == "function1"
assert result[0].subscription == AZURE_SUBSCRIPTION_ID
assert result[0].location == "West Europe"
def test_app_function_runtime_is_not_latest(self):
app_client = mock.MagicMock
with mock.patch(
"prowler.providers.common.provider.Provider.get_global_provider",
return_value=set_mocked_azure_provider(),
), mock.patch(
"prowler.providers.azure.services.app.app_function_latest_runtime_version.app_function_latest_runtime_version.app_client",
new=app_client,
):
from prowler.providers.azure.services.app.app_function_latest_runtime_version.app_function_latest_runtime_version import (
app_function_latest_runtime_version,
)
from prowler.providers.azure.services.app.app_service import FunctionApp
function_id = str(uuid4())
app_client.functions = {
AZURE_SUBSCRIPTION_ID: {
function_id: FunctionApp(
name="function1",
location="West Europe",
kind="functionapp,linux",
function_keys={},
enviroment_variables={"FUNCTIONS_EXTENSION_VERSION": "2"},
identity=None,
public_access=False,
vnet_subnet_id=None,
ftps_state="AllAllowed",
)
}
}
check = app_function_latest_runtime_version()
result = check.execute()
assert len(result) == 1
assert result[0].status == "FAIL"
assert result[0].status_extended == (
"Function function1 is not using the latest runtime. The current runtime is '2' and should be '~4'."
)
assert result[0].resource_id == function_id
assert result[0].resource_name == "function1"
assert result[0].subscription == AZURE_SUBSCRIPTION_ID
assert result[0].location == "West Europe"
@@ -0,0 +1,141 @@
from unittest import mock
from uuid import uuid4
from tests.providers.azure.azure_fixtures import (
AZURE_SUBSCRIPTION_ID,
set_mocked_azure_provider,
)
class Test_app_function_not_publicly_accessible:
def test_app_no_subscriptions(self):
app_client = mock.MagicMock
with mock.patch(
"prowler.providers.common.provider.Provider.get_global_provider",
return_value=set_mocked_azure_provider(),
), mock.patch(
"prowler.providers.azure.services.app.app_function_not_publicly_accessible.app_function_not_publicly_accessible.app_client",
new=app_client,
):
from prowler.providers.azure.services.app.app_function_not_publicly_accessible.app_function_not_publicly_accessible import (
app_function_not_publicly_accessible,
)
app_client.functions = {}
check = app_function_not_publicly_accessible()
result = check.execute()
assert len(result) == 0
def test_app_subscription_empty(self):
app_client = mock.MagicMock
with mock.patch(
"prowler.providers.common.provider.Provider.get_global_provider",
return_value=set_mocked_azure_provider(),
), mock.patch(
"prowler.providers.azure.services.app.app_function_not_publicly_accessible.app_function_not_publicly_accessible.app_client",
new=app_client,
):
from prowler.providers.azure.services.app.app_function_not_publicly_accessible.app_function_not_publicly_accessible import (
app_function_not_publicly_accessible,
)
app_client.functions = {AZURE_SUBSCRIPTION_ID: {}}
check = app_function_not_publicly_accessible()
result = check.execute()
assert len(result) == 0
def test_app_function_not_publicly_accessible(self):
app_client = mock.MagicMock
with mock.patch(
"prowler.providers.common.provider.Provider.get_global_provider",
return_value=set_mocked_azure_provider(),
), mock.patch(
"prowler.providers.azure.services.app.app_function_not_publicly_accessible.app_function_not_publicly_accessible.app_client",
new=app_client,
):
from prowler.providers.azure.services.app.app_function_not_publicly_accessible.app_function_not_publicly_accessible import (
app_function_not_publicly_accessible,
)
from prowler.providers.azure.services.app.app_service import FunctionApp
function_id = str(uuid4())
app_client.functions = {
AZURE_SUBSCRIPTION_ID: {
function_id: FunctionApp(
name="function1",
location="West Europe",
kind="functionapp,linux",
function_keys={},
enviroment_variables={},
identity=mock.MagicMock(type="SystemAssigned"),
public_access=False,
vnet_subnet_id=None,
ftps_state="AllAllowed",
)
}
}
check = app_function_not_publicly_accessible()
result = check.execute()
assert len(result) == 1
assert result[0].status == "PASS"
assert (
result[0].status_extended
== "Function function1 is not publicly accessible."
)
assert result[0].resource_name == "function1"
assert result[0].resource_id == function_id
assert result[0].subscription == AZURE_SUBSCRIPTION_ID
assert result[0].location == "West Europe"
def test_app_function_publicly_accessible(self):
app_client = mock.MagicMock
with mock.patch(
"prowler.providers.common.provider.Provider.get_global_provider",
return_value=set_mocked_azure_provider(),
), mock.patch(
"prowler.providers.azure.services.app.app_function_not_publicly_accessible.app_function_not_publicly_accessible.app_client",
new=app_client,
):
from prowler.providers.azure.services.app.app_function_not_publicly_accessible.app_function_not_publicly_accessible import (
app_function_not_publicly_accessible,
)
from prowler.providers.azure.services.app.app_service import FunctionApp
function_id = str(uuid4())
app_client.functions = {
AZURE_SUBSCRIPTION_ID: {
function_id: FunctionApp(
name="function1",
location="West Europe",
kind="functionapp,linux",
function_keys={},
enviroment_variables={},
identity=mock.MagicMock(type="SystemAssigned"),
public_access=True,
vnet_subnet_id=None,
ftps_state="AllAllowed",
)
}
}
check = app_function_not_publicly_accessible()
result = check.execute()
assert len(result) == 1
assert result[0].status == "FAIL"
assert (
result[0].status_extended
== "Function function1 is publicly accessible."
)
assert result[0].resource_name == "function1"
assert result[0].resource_id == function_id
assert result[0].subscription == AZURE_SUBSCRIPTION_ID
assert result[0].location == "West Europe"
@@ -0,0 +1,139 @@
from unittest import mock
from uuid import uuid4
from tests.providers.azure.azure_fixtures import (
AZURE_SUBSCRIPTION_ID,
set_mocked_azure_provider,
)
class Test_app_function_vnet_integration_enabled:
def test_app_no_subscriptions(self):
app_client = mock.MagicMock
with mock.patch(
"prowler.providers.common.provider.Provider.get_global_provider",
return_value=set_mocked_azure_provider(),
), mock.patch(
"prowler.providers.azure.services.app.app_function_vnet_integration_enabled.app_function_vnet_integration_enabled.app_client",
new=app_client,
):
from prowler.providers.azure.services.app.app_function_vnet_integration_enabled.app_function_vnet_integration_enabled import (
app_function_vnet_integration_enabled,
)
app_client.functions = {}
check = app_function_vnet_integration_enabled()
result = check.execute()
assert len(result) == 0
def test_app_subscription_empty(self):
app_client = mock.MagicMock
with mock.patch(
"prowler.providers.common.provider.Provider.get_global_provider",
return_value=set_mocked_azure_provider(),
), mock.patch(
"prowler.providers.azure.services.app.app_function_vnet_integration_enabled.app_function_vnet_integration_enabled.app_client",
new=app_client,
):
from prowler.providers.azure.services.app.app_function_vnet_integration_enabled.app_function_vnet_integration_enabled import (
app_function_vnet_integration_enabled,
)
app_client.functions = {AZURE_SUBSCRIPTION_ID: {}}
check = app_function_vnet_integration_enabled()
result = check.execute()
assert len(result) == 0
def test_app_function_vnet_integration_enabled(self):
app_client = mock.MagicMock
with mock.patch(
"prowler.providers.common.provider.Provider.get_global_provider",
return_value=set_mocked_azure_provider(),
), mock.patch(
"prowler.providers.azure.services.app.app_function_vnet_integration_enabled.app_function_vnet_integration_enabled.app_client",
new=app_client,
):
from prowler.providers.azure.services.app.app_function_vnet_integration_enabled.app_function_vnet_integration_enabled import (
app_function_vnet_integration_enabled,
)
from prowler.providers.azure.services.app.app_service import FunctionApp
function_id = str(uuid4())
app_client.functions = {
AZURE_SUBSCRIPTION_ID: {
function_id: FunctionApp(
name="function1",
location="West Europe",
kind="functionapp,linux",
function_keys={},
enviroment_variables={},
identity=None,
public_access=True,
vnet_subnet_id="vnet_subnet_id",
ftps_state="FtpsOnly",
)
}
}
check = app_function_vnet_integration_enabled()
result = check.execute()
assert len(result) == 1
assert result[0].status == "PASS"
assert (
result[0].status_extended
== "Function function1 has Virtual Network integration enabled with subnet 'vnet_subnet_id' enabled."
)
assert result[0].resource_name == "function1"
assert result[0].resource_id == function_id
assert result[0].location == "West Europe"
def test_app_function_vnet_integration_disabled(self):
app_client = mock.MagicMock
with mock.patch(
"prowler.providers.common.provider.Provider.get_global_provider",
return_value=set_mocked_azure_provider(),
), mock.patch(
"prowler.providers.azure.services.app.app_function_vnet_integration_enabled.app_function_vnet_integration_enabled.app_client",
new=app_client,
):
from prowler.providers.azure.services.app.app_function_vnet_integration_enabled.app_function_vnet_integration_enabled import (
app_function_vnet_integration_enabled,
)
from prowler.providers.azure.services.app.app_service import FunctionApp
function_id = str(uuid4())
app_client.functions = {
AZURE_SUBSCRIPTION_ID: {
function_id: FunctionApp(
name="function1",
location="West Europe",
kind="functionapp,linux",
function_keys={},
enviroment_variables={},
identity=None,
public_access=True,
vnet_subnet_id=None,
ftps_state="AllAllowed",
)
}
}
check = app_function_vnet_integration_enabled()
result = check.execute()
assert len(result) == 1
assert result[0].status == "FAIL"
assert (
result[0].status_extended
== "Function function1 does not have virtual network integration enabled."
)
assert result[0].resource_name == "function1"
assert result[0].resource_id == function_id
assert result[0].location == "West Europe"
@@ -8,7 +8,7 @@ from tests.providers.azure.azure_fixtures import (
set_mocked_azure_provider,
)
# TODO: we have to fix this test not to use MagicMock but set the App service while mocking the import ot the Monitor client
# TODO: we have to fix this test not to use MagicMock but set the App service while mocking the import of the Monitor client
# def mock_app_get_apps(_):
# return {
# AZURE_SUBSCRIPTION_ID: {
@@ -63,6 +63,7 @@ class Test_appinsights_ensure_is_configured:
resource_id="/subscriptions/resource_id",
resource_name="AppInsightsTest",
location="westeurope",
instrumentation_key="",
)
}
}
@@ -17,6 +17,7 @@ def mock_appinsights_get_components(_):
resource_id="/subscriptions/resource_id",
resource_name="AppInsightsTest",
location="westeurope",
instrumentation_key="",
)
}
}