fix(googleworkspace): use per-service resources for Gmail (#11169)

This commit is contained in:
lydiavilchez
2026-05-14 12:01:07 +02:00
committed by GitHub
parent 1bb547e5e1
commit 78af0c24fe
35 changed files with 94 additions and 53 deletions
@@ -3,7 +3,6 @@ from unittest.mock import patch
from prowler.providers.googleworkspace.services.gmail.gmail_service import GmailPolicies
from tests.providers.googleworkspace.googleworkspace_fixtures import (
CUSTOMER_ID,
DOMAIN,
set_mocked_googleworkspace_provider,
)
@@ -38,7 +37,7 @@ class TestGmailAnomalousAttachmentProtectionEnabled:
assert len(findings) == 1
assert findings[0].status == "PASS"
assert "WARNING" in findings[0].status_extended
assert findings[0].resource_name == DOMAIN
assert findings[0].resource_name == "Gmail Policies"
assert findings[0].customer_id == CUSTOMER_ID
def test_fail_no_action(self):
@@ -3,7 +3,6 @@ from unittest.mock import patch
from prowler.providers.googleworkspace.services.gmail.gmail_service import GmailPolicies
from tests.providers.googleworkspace.googleworkspace_fixtures import (
CUSTOMER_ID,
DOMAIN,
set_mocked_googleworkspace_provider,
)
@@ -35,10 +34,13 @@ class TestGmailAutoForwardingDisabled:
assert len(findings) == 1
assert findings[0].status == "PASS"
assert "disabled" in findings[0].status_extended
assert findings[0].resource_name == DOMAIN
assert findings[0].resource_id == CUSTOMER_ID
assert findings[0].resource_name == "Gmail Policies"
assert findings[0].resource_id == "gmailPolicies"
assert findings[0].customer_id == CUSTOMER_ID
assert findings[0].resource == mock_provider.domain_resource.dict()
assert (
findings[0].resource
== GmailPolicies(enable_auto_forwarding=False).dict()
)
def test_fail_disabled(self):
mock_provider = set_mocked_googleworkspace_provider()
@@ -3,7 +3,6 @@ from unittest.mock import patch
from prowler.providers.googleworkspace.services.gmail.gmail_service import GmailPolicies
from tests.providers.googleworkspace.googleworkspace_fixtures import (
CUSTOMER_ID,
DOMAIN,
set_mocked_googleworkspace_provider,
)
@@ -37,7 +36,7 @@ class TestGmailComprehensiveMailStorageEnabled:
assert len(findings) == 1
assert findings[0].status == "PASS"
assert "enabled" in findings[0].status_extended
assert findings[0].resource_name == DOMAIN
assert findings[0].resource_name == "Gmail Policies"
assert findings[0].customer_id == CUSTOMER_ID
def test_fail_disabled(self):
@@ -3,7 +3,6 @@ from unittest.mock import patch
from prowler.providers.googleworkspace.services.gmail.gmail_service import GmailPolicies
from tests.providers.googleworkspace.googleworkspace_fixtures import (
CUSTOMER_ID,
DOMAIN,
set_mocked_googleworkspace_provider,
)
@@ -38,7 +37,7 @@ class TestGmailDomainSpoofingProtectionEnabled:
assert len(findings) == 1
assert findings[0].status == "PASS"
assert "SPAM_FOLDER" in findings[0].status_extended
assert findings[0].resource_name == DOMAIN
assert findings[0].resource_name == "Gmail Policies"
assert findings[0].customer_id == CUSTOMER_ID
def test_fail_no_action(self):
@@ -3,7 +3,6 @@ from unittest.mock import patch
from prowler.providers.googleworkspace.services.gmail.gmail_service import GmailPolicies
from tests.providers.googleworkspace.googleworkspace_fixtures import (
CUSTOMER_ID,
DOMAIN,
set_mocked_googleworkspace_provider,
)
@@ -38,7 +37,7 @@ class TestGmailEmployeeNameSpoofingProtectionEnabled:
assert len(findings) == 1
assert findings[0].status == "PASS"
assert "SPAM_FOLDER" in findings[0].status_extended
assert findings[0].resource_name == DOMAIN
assert findings[0].resource_name == "Gmail Policies"
assert findings[0].customer_id == CUSTOMER_ID
def test_fail_no_action(self):
@@ -3,7 +3,6 @@ from unittest.mock import patch
from prowler.providers.googleworkspace.services.gmail.gmail_service import GmailPolicies
from tests.providers.googleworkspace.googleworkspace_fixtures import (
CUSTOMER_ID,
DOMAIN,
set_mocked_googleworkspace_provider,
)
@@ -38,7 +37,7 @@ class TestGmailEncryptedAttachmentProtectionEnabled:
assert len(findings) == 1
assert findings[0].status == "PASS"
assert "QUARANTINE" in findings[0].status_extended
assert findings[0].resource_name == DOMAIN
assert findings[0].resource_name == "Gmail Policies"
assert findings[0].customer_id == CUSTOMER_ID
def test_fail_no_action(self):
@@ -3,7 +3,6 @@ from unittest.mock import patch
from prowler.providers.googleworkspace.services.gmail.gmail_service import GmailPolicies
from tests.providers.googleworkspace.googleworkspace_fixtures import (
CUSTOMER_ID,
DOMAIN,
set_mocked_googleworkspace_provider,
)
@@ -37,7 +36,7 @@ class TestGmailEnhancedPreDeliveryScanningEnabled:
assert len(findings) == 1
assert findings[0].status == "PASS"
assert "enabled" in findings[0].status_extended
assert findings[0].resource_name == DOMAIN
assert findings[0].resource_name == "Gmail Policies"
assert findings[0].customer_id == CUSTOMER_ID
def test_fail_disabled(self):
@@ -3,7 +3,6 @@ from unittest.mock import patch
from prowler.providers.googleworkspace.services.gmail.gmail_service import GmailPolicies
from tests.providers.googleworkspace.googleworkspace_fixtures import (
CUSTOMER_ID,
DOMAIN,
set_mocked_googleworkspace_provider,
)
@@ -35,7 +34,7 @@ class TestGmailExternalImageScanningEnabled:
assert len(findings) == 1
assert findings[0].status == "PASS"
assert "enabled" in findings[0].status_extended
assert findings[0].resource_name == DOMAIN
assert findings[0].resource_name == "Gmail Policies"
assert findings[0].customer_id == CUSTOMER_ID
def test_fail_disabled(self):
@@ -3,7 +3,6 @@ from unittest.mock import patch
from prowler.providers.googleworkspace.services.gmail.gmail_service import GmailPolicies
from tests.providers.googleworkspace.googleworkspace_fixtures import (
CUSTOMER_ID,
DOMAIN,
set_mocked_googleworkspace_provider,
)
@@ -39,7 +38,7 @@ class TestGmailGroupsSpoofingProtectionEnabled:
assert findings[0].status == "PASS"
assert "all groups" in findings[0].status_extended
assert "SPAM_FOLDER" in findings[0].status_extended
assert findings[0].resource_name == DOMAIN
assert findings[0].resource_name == "Gmail Policies"
assert findings[0].customer_id == CUSTOMER_ID
def test_pass_private_groups_only(self):
@@ -3,7 +3,6 @@ from unittest.mock import patch
from prowler.providers.googleworkspace.services.gmail.gmail_service import GmailPolicies
from tests.providers.googleworkspace.googleworkspace_fixtures import (
CUSTOMER_ID,
DOMAIN,
set_mocked_googleworkspace_provider,
)
@@ -38,7 +37,7 @@ class TestGmailInboundDomainSpoofingProtectionEnabled:
assert len(findings) == 1
assert findings[0].status == "PASS"
assert "QUARANTINE" in findings[0].status_extended
assert findings[0].resource_name == DOMAIN
assert findings[0].resource_name == "Gmail Policies"
assert findings[0].customer_id == CUSTOMER_ID
def test_fail_no_action(self):
@@ -3,7 +3,6 @@ from unittest.mock import patch
from prowler.providers.googleworkspace.services.gmail.gmail_service import GmailPolicies
from tests.providers.googleworkspace.googleworkspace_fixtures import (
CUSTOMER_ID,
DOMAIN,
set_mocked_googleworkspace_provider,
)
@@ -35,7 +34,7 @@ class TestGmailMailDelegationDisabled:
assert len(findings) == 1
assert findings[0].status == "PASS"
assert "disabled" in findings[0].status_extended
assert findings[0].resource_name == DOMAIN
assert findings[0].resource_name == "Gmail Policies"
assert findings[0].customer_id == CUSTOMER_ID
def test_fail_delegation_enabled(self):
@@ -3,7 +3,6 @@ from unittest.mock import patch
from prowler.providers.googleworkspace.services.gmail.gmail_service import GmailPolicies
from tests.providers.googleworkspace.googleworkspace_fixtures import (
CUSTOMER_ID,
DOMAIN,
set_mocked_googleworkspace_provider,
)
@@ -35,7 +34,7 @@ class TestGmailPerUserOutboundGatewayDisabled:
assert len(findings) == 1
assert findings[0].status == "PASS"
assert "disabled" in findings[0].status_extended
assert findings[0].resource_name == DOMAIN
assert findings[0].resource_name == "Gmail Policies"
assert findings[0].customer_id == CUSTOMER_ID
def test_fail_disabled(self):
@@ -3,7 +3,6 @@ from unittest.mock import patch
from prowler.providers.googleworkspace.services.gmail.gmail_service import GmailPolicies
from tests.providers.googleworkspace.googleworkspace_fixtures import (
CUSTOMER_ID,
DOMAIN,
set_mocked_googleworkspace_provider,
)
@@ -37,7 +36,7 @@ class TestGmailPopImapAccessDisabled:
assert len(findings) == 1
assert findings[0].status == "PASS"
assert "disabled" in findings[0].status_extended
assert findings[0].resource_name == DOMAIN
assert findings[0].resource_name == "Gmail Policies"
assert findings[0].customer_id == CUSTOMER_ID
def test_fail_both_enabled(self):
@@ -3,7 +3,6 @@ from unittest.mock import patch
from prowler.providers.googleworkspace.services.gmail.gmail_service import GmailPolicies
from tests.providers.googleworkspace.googleworkspace_fixtures import (
CUSTOMER_ID,
DOMAIN,
set_mocked_googleworkspace_provider,
)
@@ -38,7 +37,7 @@ class TestGmailScriptAttachmentProtectionEnabled:
assert len(findings) == 1
assert findings[0].status == "PASS"
assert "QUARANTINE" in findings[0].status_extended
assert findings[0].resource_name == DOMAIN
assert findings[0].resource_name == "Gmail Policies"
assert findings[0].customer_id == CUSTOMER_ID
def test_fail_no_action(self):
@@ -3,7 +3,6 @@ from unittest.mock import patch
from prowler.providers.googleworkspace.services.gmail.gmail_service import GmailPolicies
from tests.providers.googleworkspace.googleworkspace_fixtures import (
CUSTOMER_ID,
DOMAIN,
set_mocked_googleworkspace_provider,
)
@@ -35,7 +34,7 @@ class TestGmailShortenerScanningEnabled:
assert len(findings) == 1
assert findings[0].status == "PASS"
assert "enabled" in findings[0].status_extended
assert findings[0].resource_name == DOMAIN
assert findings[0].resource_name == "Gmail Policies"
assert findings[0].customer_id == CUSTOMER_ID
def test_fail_disabled(self):
@@ -3,7 +3,6 @@ from unittest.mock import patch
from prowler.providers.googleworkspace.services.gmail.gmail_service import GmailPolicies
from tests.providers.googleworkspace.googleworkspace_fixtures import (
CUSTOMER_ID,
DOMAIN,
set_mocked_googleworkspace_provider,
)
@@ -38,7 +37,7 @@ class TestGmailUnauthenticatedEmailProtectionEnabled:
assert len(findings) == 1
assert findings[0].status == "PASS"
assert "WARNING" in findings[0].status_extended
assert findings[0].resource_name == DOMAIN
assert findings[0].resource_name == "Gmail Policies"
assert findings[0].customer_id == CUSTOMER_ID
def test_fail_no_action(self):
@@ -3,7 +3,6 @@ from unittest.mock import patch
from prowler.providers.googleworkspace.services.gmail.gmail_service import GmailPolicies
from tests.providers.googleworkspace.googleworkspace_fixtures import (
CUSTOMER_ID,
DOMAIN,
set_mocked_googleworkspace_provider,
)
@@ -37,7 +36,7 @@ class TestGmailUntrustedLinkWarningsEnabled:
assert len(findings) == 1
assert findings[0].status == "PASS"
assert "enabled" in findings[0].status_extended
assert findings[0].resource_name == DOMAIN
assert findings[0].resource_name == "Gmail Policies"
assert findings[0].customer_id == CUSTOMER_ID
def test_fail_disabled(self):