From 902558f2d4cac81afab3423497897c491c153376 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Adri=C3=A1n=20Pe=C3=B1a?= Date: Thu, 26 Feb 2026 12:27:52 +0100 Subject: [PATCH] feat(api): block attack-paths-scans custom queries and schema endpoints (#10177) --- api/CHANGELOG.md | 2 +- api/src/backend/api/tests/test_views.py | 8 ++++++++ api/src/backend/api/v1/urls.py | 23 +++++++++++++++++++++++ 3 files changed, 32 insertions(+), 1 deletion(-) diff --git a/api/CHANGELOG.md b/api/CHANGELOG.md index 535617da89..fbd8794c31 100644 --- a/api/CHANGELOG.md +++ b/api/CHANGELOG.md @@ -10,7 +10,7 @@ All notable changes to the **Prowler API** are documented in this file. - OpenStack provider support [(#10003)](https://github.com/prowler-cloud/prowler/pull/10003) - PDF report for the CSA CCM compliance framework [(#10088)](https://github.com/prowler-cloud/prowler/pull/10088) - `image` provider support for container image scanning [(#10128)](https://github.com/prowler-cloud/prowler/pull/10128) -- Attack Paths: Custom query and Cartography schema endpoints [(#10149)](https://github.com/prowler-cloud/prowler/pull/10149) +- Attack Paths: Custom query and Cartography schema endpoints (temporarily blocked) [(#10149)](https://github.com/prowler-cloud/prowler/pull/10149) ### 🔄 Changed diff --git a/api/src/backend/api/tests/test_views.py b/api/src/backend/api/tests/test_views.py index fe60def170..5130525342 100644 --- a/api/src/backend/api/tests/test_views.py +++ b/api/src/backend/api/tests/test_views.py @@ -4280,6 +4280,8 @@ class TestAttackPathsScanViewSet: } } + # TODO: Remove skip once queries/custom and schema endpoints are unblocked + @pytest.mark.skip(reason="Endpoint temporarily blocked") def test_run_custom_query_returns_graph( self, authenticated_client, @@ -4337,6 +4339,7 @@ class TestAttackPathsScanViewSet: assert attributes["total_nodes"] == 1 assert attributes["truncated"] is False + @pytest.mark.skip(reason="Endpoint temporarily blocked") def test_run_custom_query_returns_404_when_no_nodes( self, authenticated_client, @@ -4378,6 +4381,7 @@ class TestAttackPathsScanViewSet: assert response.status_code == status.HTTP_404_NOT_FOUND + @pytest.mark.skip(reason="Endpoint temporarily blocked") def test_run_custom_query_returns_400_when_graph_not_ready( self, authenticated_client, @@ -4404,6 +4408,7 @@ class TestAttackPathsScanViewSet: assert response.status_code == status.HTTP_400_BAD_REQUEST assert "not available" in response.json()["errors"][0]["detail"] + @pytest.mark.skip(reason="Endpoint temporarily blocked") def test_run_custom_query_returns_403_for_write_query( self, authenticated_client, @@ -4443,6 +4448,7 @@ class TestAttackPathsScanViewSet: # -- cartography_schema action ------------------------------------------------ + @pytest.mark.skip(reason="Endpoint temporarily blocked") def test_cartography_schema_returns_urls( self, authenticated_client, @@ -4492,6 +4498,7 @@ class TestAttackPathsScanViewSet: assert "schema.md" in attributes["schema_url"] assert "raw.githubusercontent.com" in attributes["raw_schema_url"] + @pytest.mark.skip(reason="Endpoint temporarily blocked") def test_cartography_schema_returns_404_when_no_metadata( self, authenticated_client, @@ -4526,6 +4533,7 @@ class TestAttackPathsScanViewSet: assert response.status_code == status.HTTP_404_NOT_FOUND assert "No cartography schema metadata" in str(response.json()) + @pytest.mark.skip(reason="Endpoint temporarily blocked") def test_cartography_schema_returns_400_when_graph_not_ready( self, authenticated_client, diff --git a/api/src/backend/api/v1/urls.py b/api/src/backend/api/v1/urls.py index f2578c9d95..bbe5d08167 100644 --- a/api/src/backend/api/v1/urls.py +++ b/api/src/backend/api/v1/urls.py @@ -1,5 +1,7 @@ from allauth.socialaccount.providers.saml.views import ACSView, MetadataView, SLSView +from django.http import JsonResponse from django.urls import include, path +from django.views.decorators.csrf import csrf_exempt from drf_spectacular.views import SpectacularRedocView from rest_framework_nested import routers @@ -48,6 +50,16 @@ from api.v1.views import ( UserViewSet, ) + +@csrf_exempt +def _blocked_endpoint(request, *args, **kwargs): + return JsonResponse( + {"errors": [{"detail": "This endpoint is not available."}]}, + status=405, + content_type="application/vnd.api+json", + ) + + router = routers.DefaultRouter(trailing_slash=False) router.register(r"users", UserViewSet, basename="user") @@ -197,6 +209,17 @@ urlpatterns = [ path("tokens/saml", SAMLTokenValidateView.as_view(), name="token-saml"), path("tokens/google", GoogleSocialLoginView.as_view(), name="token-google"), path("tokens/github", GithubSocialLoginView.as_view(), name="token-github"), + # TODO: Remove these blocked endpoints once they are properly tested + path( + "attack-paths-scans//queries/custom", + _blocked_endpoint, + name="attack-paths-scans-queries-custom-blocked", + ), + path( + "attack-paths-scans//schema", + _blocked_endpoint, + name="attack-paths-scans-schema-blocked", + ), path("", include(router.urls)), path("", include(tenants_router.urls)), path("", include(users_router.urls)),