mirror of
https://github.com/prowler-cloud/prowler.git
synced 2026-10-09 21:14:22 +00:00
fix(gcp): match enable-oslogin metadata case-insensitively (#11341)
Co-authored-by: Hugo Pereira Brito <101209179+HugoPBrito@users.noreply.github.com>
This commit is contained in:
1 parent
00451f8239
commit
d560020592
4 files changed
+20
-4
No files matched your search
@@ -11,10 +11,11 @@ All notable changes to the **Prowler SDK** are documented in this file.
|
||||
|
||||
---
|
||||
|
||||
## [5.28.1] (Prowler v5.28.1)
|
||||
## [5.28.1] (Prowler UNRELEASED)
|
||||
|
||||
### 🐞 Fixed
|
||||
|
||||
- `compute_project_os_login_enabled` and `compute_project_os_login_2fa_enabled` checks for GCP provider no longer false-FAIL on projects where the `enable-oslogin` / `enable-oslogin-2fa` metadata is not set explicitly but is inherited automatically from the `constraints/compute.requireOsLogin` org policy. The policy controller writes the inherited value in lowercase (`"true"`), but the service-layer parser compared it to the uppercase string literal `"TRUE"`. Comparison is now case-insensitive [(#11341)](https://github.com/prowler-cloud/prowler/pull/11341)
|
||||
- `storage_smb_channel_encryption_with_secure_algorithm` check for Azure provider no longer passes when a storage account allows a weak SMB channel encryption algorithm (e.g. `AES-128-CCM`/`AES-128-GCM`) alongside `AES-256-GCM`; it now requires every enabled algorithm to be in the recommended list, configurable via `azure.recommended_smb_channel_encryption_algorithms` (defaults to `AES-256-GCM` only, as required by CIS) [(#11327)](https://github.com/prowler-cloud/prowler/pull/11327)
|
||||
|
||||
---
|
||||
|
||||
@@ -87,9 +87,15 @@ class Compute(GCPService):
|
||||
.execute(num_retries=DEFAULT_RETRY_ATTEMPTS)
|
||||
)
|
||||
for item in response["commonInstanceMetadata"].get("items", []):
|
||||
if item["key"] == "enable-oslogin" and item["value"] == "TRUE":
|
||||
if (
|
||||
item["key"] == "enable-oslogin"
|
||||
and item["value"].lower() == "true"
|
||||
):
|
||||
enable_oslogin = True
|
||||
if item["key"] == "enable-oslogin-2fa" and item["value"] == "TRUE":
|
||||
if (
|
||||
item["key"] == "enable-oslogin-2fa"
|
||||
and item["value"].lower() == "true"
|
||||
):
|
||||
enable_oslogin_2fa = True
|
||||
self.compute_projects.append(
|
||||
Project(
|
||||
|
||||
@@ -126,7 +126,11 @@ def mock_api_projects_calls(client: MagicMock):
|
||||
"etag": "BwWWja0YfJA=",
|
||||
"version": 3,
|
||||
}
|
||||
# Used by compute client and cloudresourcemanager
|
||||
# Used by compute client and cloudresourcemanager.
|
||||
# `enable-oslogin` covers the documented uppercase form (TRUE);
|
||||
# `enable-oslogin-2fa` covers the lowercase form (true) that GCP's
|
||||
# `constraints/compute.requireOsLogin` org-policy controller writes
|
||||
# in production. The service-layer parser must handle both casings.
|
||||
client.projects().get().execute.return_value = {
|
||||
"projectNumber": "123456789012",
|
||||
"commonInstanceMetadata": {
|
||||
@@ -139,6 +143,10 @@ def mock_api_projects_calls(client: MagicMock):
|
||||
"key": "enable-oslogin",
|
||||
"value": "FALSE",
|
||||
},
|
||||
{
|
||||
"key": "enable-oslogin-2fa",
|
||||
"value": "true",
|
||||
},
|
||||
{
|
||||
"key": "testing-key",
|
||||
"value": "TRUE",
|
||||
|
||||
@@ -34,6 +34,7 @@ class TestComputeService:
|
||||
assert len(compute_client.compute_projects) == 1
|
||||
assert compute_client.compute_projects[0].id == GCP_PROJECT_ID
|
||||
assert compute_client.compute_projects[0].enable_oslogin
|
||||
assert compute_client.compute_projects[0].enable_oslogin_2fa
|
||||
|
||||
assert len(compute_client.instances) == 2
|
||||
assert compute_client.instances[0].name == "instance1"
|
||||
|
||||
Reference in new issue
Block a user