mirror of
https://github.com/prowler-cloud/prowler.git
synced 2026-10-04 02:04:06 +00:00
fix(sdk): report all-users 2sv override failures (#12700)
This commit is contained in:
@@ -0,0 +1 @@
|
||||
`security_2sv_enforced` reports domain-wide 2-Step Verification failures as FAIL even when every failing setting is overridden for a group or organizational unit
|
||||
+1
-16
@@ -8,7 +8,6 @@ from prowler.providers.googleworkspace.services.security.lib.durations import (
|
||||
parse_duration_seconds,
|
||||
)
|
||||
from prowler.providers.googleworkspace.services.security.lib.scope import (
|
||||
failures_shadowed_by_overrides,
|
||||
override_caveat,
|
||||
unevaluable_reason,
|
||||
)
|
||||
@@ -145,23 +144,9 @@ class security_2sv_enforced(Check):
|
||||
)
|
||||
)
|
||||
|
||||
failing_settings = frozenset(setting for setting, _ in issues)
|
||||
reasons = "; ".join(text for _, text in issues)
|
||||
|
||||
if issues and failures_shadowed_by_overrides(policies, failing_settings):
|
||||
# The audited scope (e.g. the admin group of 4.1.1.1) may get
|
||||
# the overriding value, which the Policy API does not expose,
|
||||
# so the domain-wide failure cannot be confirmed for it.
|
||||
report.status = "MANUAL"
|
||||
report.status_extended = (
|
||||
f"2-Step Verification is not enforced as required in the "
|
||||
f"domain-wide policy of {domain}: {reasons}. However, every "
|
||||
f"failing setting is also overridden for at least one group "
|
||||
f"or organizational unit, so the audited scope may be "
|
||||
f"configured correctly. Review those overrides in the Admin "
|
||||
f"console."
|
||||
)
|
||||
elif issues:
|
||||
if issues:
|
||||
report.status = "FAIL"
|
||||
report.status_extended = (
|
||||
f"2-Step Verification is not enforced as required in domain "
|
||||
|
||||
+4
-6
@@ -224,8 +224,8 @@ class TestSecurity2svEnforced:
|
||||
assert "trust their device" in findings[0].status_extended
|
||||
assert "also overridden" in findings[0].status_extended
|
||||
|
||||
def test_manual_when_every_failing_setting_is_overridden(self):
|
||||
"""The overriding value is not exposed, so the failure is unconfirmed"""
|
||||
def test_fail_when_every_failing_setting_is_overridden(self):
|
||||
"""The all-users requirement still fails for users outside the override"""
|
||||
findings = run_check(
|
||||
**{
|
||||
**COMPLIANT,
|
||||
@@ -235,11 +235,9 @@ class TestSecurity2svEnforced:
|
||||
)
|
||||
|
||||
assert len(findings) == 1
|
||||
assert findings[0].status == "MANUAL"
|
||||
assert findings[0].status == "FAIL"
|
||||
assert "trust their device" in findings[0].status_extended
|
||||
assert "every failing setting is also overridden" in (
|
||||
findings[0].status_extended
|
||||
)
|
||||
assert "also overridden" in findings[0].status_extended
|
||||
|
||||
def test_fail_when_only_some_failing_settings_are_overridden(self):
|
||||
"""A failure no override reaches is still proven for the whole domain"""
|
||||
|
||||
Reference in New Issue
Block a user