fix(gcp): match enable-oslogin metadata case-insensitively (#11341)

Co-authored-by: Hugo Pereira Brito <101209179+HugoPBrito@users.noreply.github.com>
This commit is contained in:
Aline AlmeidaandHugo Pereira Brito authored and GitHub committed 2026-05-26 10:35:26 +02:00
1 parent 00451f8239
commit d560020592
4 files changed
+20 -4

No files matched your search

+2 -1
View File
@@ -11,10 +11,11 @@ All notable changes to the **Prowler SDK** are documented in this file.
---
## [5.28.1] (Prowler v5.28.1)
## [5.28.1] (Prowler UNRELEASED)
### 🐞 Fixed
- `compute_project_os_login_enabled` and `compute_project_os_login_2fa_enabled` checks for GCP provider no longer false-FAIL on projects where the `enable-oslogin` / `enable-oslogin-2fa` metadata is not set explicitly but is inherited automatically from the `constraints/compute.requireOsLogin` org policy. The policy controller writes the inherited value in lowercase (`"true"`), but the service-layer parser compared it to the uppercase string literal `"TRUE"`. Comparison is now case-insensitive [(#11341)](https://github.com/prowler-cloud/prowler/pull/11341)
- `storage_smb_channel_encryption_with_secure_algorithm` check for Azure provider no longer passes when a storage account allows a weak SMB channel encryption algorithm (e.g. `AES-128-CCM`/`AES-128-GCM`) alongside `AES-256-GCM`; it now requires every enabled algorithm to be in the recommended list, configurable via `azure.recommended_smb_channel_encryption_algorithms` (defaults to `AES-256-GCM` only, as required by CIS) [(#11327)](https://github.com/prowler-cloud/prowler/pull/11327)
---
@@ -87,9 +87,15 @@ class Compute(GCPService):
.execute(num_retries=DEFAULT_RETRY_ATTEMPTS)
)
for item in response["commonInstanceMetadata"].get("items", []):
if item["key"] == "enable-oslogin" and item["value"] == "TRUE":
if (
item["key"] == "enable-oslogin"
and item["value"].lower() == "true"
):
enable_oslogin = True
if item["key"] == "enable-oslogin-2fa" and item["value"] == "TRUE":
if (
item["key"] == "enable-oslogin-2fa"
and item["value"].lower() == "true"
):
enable_oslogin_2fa = True
self.compute_projects.append(
Project(
+9 -1
View File
@@ -126,7 +126,11 @@ def mock_api_projects_calls(client: MagicMock):
"etag": "BwWWja0YfJA=",
"version": 3,
}
# Used by compute client and cloudresourcemanager
# Used by compute client and cloudresourcemanager.
# `enable-oslogin` covers the documented uppercase form (TRUE);
# `enable-oslogin-2fa` covers the lowercase form (true) that GCP's
# `constraints/compute.requireOsLogin` org-policy controller writes
# in production. The service-layer parser must handle both casings.
client.projects().get().execute.return_value = {
"projectNumber": "123456789012",
"commonInstanceMetadata": {
@@ -139,6 +143,10 @@ def mock_api_projects_calls(client: MagicMock):
"key": "enable-oslogin",
"value": "FALSE",
},
{
"key": "enable-oslogin-2fa",
"value": "true",
},
{
"key": "testing-key",
"value": "TRUE",
@@ -34,6 +34,7 @@ class TestComputeService:
assert len(compute_client.compute_projects) == 1
assert compute_client.compute_projects[0].id == GCP_PROJECT_ID
assert compute_client.compute_projects[0].enable_oslogin
assert compute_client.compute_projects[0].enable_oslogin_2fa
assert len(compute_client.instances) == 2
assert compute_client.instances[0].name == "instance1"