fix(sdk): report all-users 2sv override failures (#12700)

This commit is contained in:
Haitao Zheng
2026-09-17 13:19:11 +02:00
committed by GitHub
parent f382400037
commit d0d29108e0
3 changed files with 6 additions and 22 deletions
@@ -0,0 +1 @@
`security_2sv_enforced` reports domain-wide 2-Step Verification failures as FAIL even when every failing setting is overridden for a group or organizational unit
@@ -8,7 +8,6 @@ from prowler.providers.googleworkspace.services.security.lib.durations import (
parse_duration_seconds,
)
from prowler.providers.googleworkspace.services.security.lib.scope import (
failures_shadowed_by_overrides,
override_caveat,
unevaluable_reason,
)
@@ -145,23 +144,9 @@ class security_2sv_enforced(Check):
)
)
failing_settings = frozenset(setting for setting, _ in issues)
reasons = "; ".join(text for _, text in issues)
if issues and failures_shadowed_by_overrides(policies, failing_settings):
# The audited scope (e.g. the admin group of 4.1.1.1) may get
# the overriding value, which the Policy API does not expose,
# so the domain-wide failure cannot be confirmed for it.
report.status = "MANUAL"
report.status_extended = (
f"2-Step Verification is not enforced as required in the "
f"domain-wide policy of {domain}: {reasons}. However, every "
f"failing setting is also overridden for at least one group "
f"or organizational unit, so the audited scope may be "
f"configured correctly. Review those overrides in the Admin "
f"console."
)
elif issues:
if issues:
report.status = "FAIL"
report.status_extended = (
f"2-Step Verification is not enforced as required in domain "
@@ -224,8 +224,8 @@ class TestSecurity2svEnforced:
assert "trust their device" in findings[0].status_extended
assert "also overridden" in findings[0].status_extended
def test_manual_when_every_failing_setting_is_overridden(self):
"""The overriding value is not exposed, so the failure is unconfirmed"""
def test_fail_when_every_failing_setting_is_overridden(self):
"""The all-users requirement still fails for users outside the override"""
findings = run_check(
**{
**COMPLIANT,
@@ -235,11 +235,9 @@ class TestSecurity2svEnforced:
)
assert len(findings) == 1
assert findings[0].status == "MANUAL"
assert findings[0].status == "FAIL"
assert "trust their device" in findings[0].status_extended
assert "every failing setting is also overridden" in (
findings[0].status_extended
)
assert "also overridden" in findings[0].status_extended
def test_fail_when_only_some_failing_settings_are_overridden(self):
"""A failure no override reaches is still proven for the whole domain"""