diff --git a/docs/images/providers/cloudflare-token-permissions.png b/docs/images/providers/cloudflare-token-permissions.png index 49926f0415..59634d0df1 100644 Binary files a/docs/images/providers/cloudflare-token-permissions.png and b/docs/images/providers/cloudflare-token-permissions.png differ diff --git a/docs/user-guide/providers/cloudflare/authentication.mdx b/docs/user-guide/providers/cloudflare/authentication.mdx index 37e2ffafef..78b8a1e5af 100644 --- a/docs/user-guide/providers/cloudflare/authentication.mdx +++ b/docs/user-guide/providers/cloudflare/authentication.mdx @@ -22,9 +22,12 @@ Prowler requires read-only access to Cloudflare zones and their settings. The fo | Resource | Permission | Access | Description | |----------|------------|--------|-------------| | `Account` | `Account Settings` | `Read` | Required to list accounts and verify user identity | -| `Zone` | `Zone` | `Read` | Required to list zones, rulesets, bot management, and SSL settings | -| `Zone` | `Zone Settings` | `Read` | Required to read zone security settings (TLS, HSTS, WAF, etc.) | -| `Zone` | `DNS` | `Read` | Required to read DNS records and DNSSEC status | +| `Zone` | `Zone` | `Read` | Required to list zones | +| `Zone` | `Zone Settings` | `Read` | Required to read zone security settings (SSL/TLS mode, TLS versions, HSTS, Always Use HTTPS, WAF, etc.) | +| `Zone` | `DNS` | `Read` | Required to read DNS records (SPF, DMARC, DKIM, CAA) and DNSSEC status | +| `Zone` | `SSL and Certificates` | `Read` | Required to read Universal SSL settings | +| `Zone` | `Bot Management` | `Read` | Required to read Bot Fight Mode | +| `Zone` | `Zone WAF` | `Read` | Required to read WAF custom, rate limiting, and managed rulesets | Ensure the API Token has access to all zones targeted for scanning. Missing permissions may cause some checks to fail or return incomplete results. @@ -46,8 +49,8 @@ Create a **User API Token**, not an Account API Token. User API Tokens are creat **Quick Setup:** Use these pre-configured links to open the Cloudflare Dashboard with the required permissions already selected: -- [Create User API Token](https://dash.cloudflare.com/profile/api-tokens?permissionGroupKeys=%5B%7B%22key%22%3A%22account_settings%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22zone%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22zone_settings%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22dns%22%2C%22type%22%3A%22read%22%7D%5D&accountId=%2A&zoneId=all&name=Prowler%20Security%20Scanner) — creates a **User API Token** (recommended). Opens the **Create Custom Token** form prefilled with the four required read-only scopes (`Account Settings`, `Zone`, `Zone Settings`, `DNS`) and the name `Prowler Security Scanner`. Adjust **Account Resources** and **Zone Resources** to match the accounts and zones you want to scan, then click **Create Token**. -- [Create Account-Owned API Token](https://dash.cloudflare.com/?to=/:account/api-tokens&permissionGroupKeys=%5B%7B%22key%22%3A%22account_settings%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22zone%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22zone_settings%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22dns%22%2C%22type%22%3A%22read%22%7D%5D&name=Prowler%20Security%20Scanner) — creates an [account-owned token](https://developers.cloudflare.com/fundamentals/api/how-to/account-owned-token-template/) instead. Use this for automation or CI/CD where the token should not depend on a specific user account remaining active. Requires the **Super Administrator** or **Administrator** role on the account. +- [Create User API Token](https://dash.cloudflare.com/profile/api-tokens?permissionGroupKeys=%5B%7B%22key%22%3A%22account_settings%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22zone%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22zone_settings%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22dns%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22ssl_and_certificates%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22bot_management%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22zone_waf%22%2C%22type%22%3A%22read%22%7D%5D&accountId=%2A&zoneId=all&name=Prowler%20Security%20Scanner) — creates a **User API Token** (recommended). Opens the **Create Custom Token** form prefilled with the seven required read-only scopes (`Account Settings`, `Zone`, `Zone Settings`, `DNS`, `SSL and Certificates`, `Bot Management`, `Zone WAF`) and the name `Prowler Security Scanner`. Adjust **Account Resources** and **Zone Resources** to match the accounts and zones you want to scan, then click **Create Token**. +- [Create Account-Owned API Token](https://dash.cloudflare.com/?to=/:account/api-tokens&permissionGroupKeys=%5B%7B%22key%22%3A%22account_settings%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22zone%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22zone_settings%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22dns%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22ssl_and_certificates%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22bot_management%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22zone_waf%22%2C%22type%22%3A%22read%22%7D%5D&name=Prowler%20Security%20Scanner) — creates an [account-owned token](https://developers.cloudflare.com/fundamentals/api/how-to/account-owned-token-template/) instead. Use this for automation or CI/CD where the token should not depend on a specific user account remaining active. Requires the **Super Administrator** or **Administrator** role on the account. Template URLs only pre-fill the token creation form. Review the permissions, configure resources, and click **Create Token** to complete the process. @@ -66,6 +69,9 @@ Template URLs only pre-fill the token creation form. Review the permissions, con - `Zone` — `Zone` — `Read` - `Zone` — `Zone Settings` — `Read` - `Zone` — `DNS` — `Read` + - `Zone` — `SSL and Certificates` — `Read` + - `Zone` — `Bot Management` — `Read` + - `Zone` — `Zone WAF` — `Read` - **Zone Resources:** Select either: - **Include → All zones** (to scan all zones in the account) - **Include → Specific zone** (to limit access to specific zones) diff --git a/docs/user-guide/providers/cloudflare/getting-started-cloudflare.mdx b/docs/user-guide/providers/cloudflare/getting-started-cloudflare.mdx index 9af3dbe589..efdae635cc 100644 --- a/docs/user-guide/providers/cloudflare/getting-started-cloudflare.mdx +++ b/docs/user-guide/providers/cloudflare/getting-started-cloudflare.mdx @@ -11,16 +11,16 @@ Prowler for Cloudflare scans zones for security misconfigurations, including SSL Set up authentication for Cloudflare with the [Cloudflare Authentication](/user-guide/providers/cloudflare/authentication) guide before starting either path: - Create a Cloudflare User API Token (recommended) or locate the Global API Key -- Grant the required read-only permissions (`Account Settings:Read`, `Zone:Read`, `Zone Settings:Read`, `DNS:Read`) +- Grant the required read-only permissions (`Account Settings:Read`, `Zone:Read`, `Zone Settings:Read`, `DNS:Read`, `SSL and Certificates:Read`, `Bot Management:Read`, `Zone WAF:Read`) - Identify the Cloudflare Account ID to use as the provider identifier **Quick Setup:** Use these pre-configured links to create a token with the required permissions already selected: -- [Create User API Token](https://dash.cloudflare.com/profile/api-tokens?permissionGroupKeys=%5B%7B%22key%22%3A%22account_settings%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22zone%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22zone_settings%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22dns%22%2C%22type%22%3A%22read%22%7D%5D&accountId=%2A&zoneId=all&name=Prowler%20Security%20Scanner) — creates a User API Token (recommended). -- [Create Account-Owned API Token](https://dash.cloudflare.com/?to=/:account/api-tokens&permissionGroupKeys=%5B%7B%22key%22%3A%22account_settings%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22zone%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22zone_settings%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22dns%22%2C%22type%22%3A%22read%22%7D%5D&name=Prowler%20Security%20Scanner) — creates an [account-owned token](https://developers.cloudflare.com/fundamentals/api/how-to/account-owned-token-template/), better suited for automation and CI/CD. +- [Create User API Token](https://dash.cloudflare.com/profile/api-tokens?permissionGroupKeys=%5B%7B%22key%22%3A%22account_settings%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22zone%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22zone_settings%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22dns%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22ssl_and_certificates%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22bot_management%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22zone_waf%22%2C%22type%22%3A%22read%22%7D%5D&accountId=%2A&zoneId=all&name=Prowler%20Security%20Scanner) — creates a User API Token (recommended). +- [Create Account-Owned API Token](https://dash.cloudflare.com/?to=/:account/api-tokens&permissionGroupKeys=%5B%7B%22key%22%3A%22account_settings%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22zone%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22zone_settings%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22dns%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22ssl_and_certificates%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22bot_management%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22zone_waf%22%2C%22type%22%3A%22read%22%7D%5D&name=Prowler%20Security%20Scanner) — creates an [account-owned token](https://developers.cloudflare.com/fundamentals/api/how-to/account-owned-token-template/), better suited for automation and CI/CD. -Both links open the Cloudflare Dashboard with the four required read-only scopes (`Account Settings`, `Zone`, `Zone Settings`, `DNS`) and the name `Prowler Security Scanner` prefilled. See [Cloudflare Authentication](/user-guide/providers/cloudflare/authentication#api-token-recommended) for the equivalent manual steps. +Both links open the Cloudflare Dashboard with the seven required read-only scopes (`Account Settings`, `Zone`, `Zone Settings`, `DNS`, `SSL and Certificates`, `Bot Management`, `Zone WAF`) and the name `Prowler Security Scanner` prefilled. See [Cloudflare Authentication](/user-guide/providers/cloudflare/authentication#api-token-recommended) for the equivalent manual steps. diff --git a/docs/user-guide/tutorials/prowler-app-github-action.mdx b/docs/user-guide/tutorials/prowler-app-github-action.mdx index faf0993e21..f48e0f806b 100644 --- a/docs/user-guide/tutorials/prowler-app-github-action.mdx +++ b/docs/user-guide/tutorials/prowler-app-github-action.mdx @@ -241,7 +241,7 @@ steps: ### Cloudflare -Create a Cloudflare API Token with `Zone:Read`, `Zone Settings:Read`, and `DNS:Read` permissions ([provider auth docs](/user-guide/providers/cloudflare/authentication)). Then: +Create a Cloudflare API Token with the `Account Settings:Read`, `Zone:Read`, `Zone Settings:Read`, `DNS:Read`, `SSL and Certificates:Read`, `Bot Management:Read`, and `Zone WAF:Read` permissions ([provider auth docs](/user-guide/providers/cloudflare/authentication)). Then: ```yaml - uses: prowler-cloud/prowler@5.25 diff --git a/ui/changelog.d/cloudflare-token-permissions.fixed.md b/ui/changelog.d/cloudflare-token-permissions.fixed.md new file mode 100644 index 0000000000..9a862ee88c --- /dev/null +++ b/ui/changelog.d/cloudflare-token-permissions.fixed.md @@ -0,0 +1 @@ +Cloudflare API token links in the provider wizard request the SSL and Certificates, Bot Management and Zone WAF read permissions the scan needs diff --git a/ui/components/providers/workflow/forms/select-credentials-type/cloudflare/credentials-type/cloudflare-api-token-credentials-form.test.tsx b/ui/components/providers/workflow/forms/select-credentials-type/cloudflare/credentials-type/cloudflare-api-token-credentials-form.test.tsx index d8278030f4..d51cf47ff1 100644 --- a/ui/components/providers/workflow/forms/select-credentials-type/cloudflare/credentials-type/cloudflare-api-token-credentials-form.test.tsx +++ b/ui/components/providers/workflow/forms/select-credentials-type/cloudflare/credentials-type/cloudflare-api-token-credentials-form.test.tsx @@ -21,7 +21,7 @@ const Harness = ({ providerUid }: { providerUid?: string }) => { }; const USER_URL = - "https://dash.cloudflare.com/profile/api-tokens?permissionGroupKeys=%5B%7B%22key%22%3A%22account_settings%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22zone%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22zone_settings%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22dns%22%2C%22type%22%3A%22read%22%7D%5D&accountId=%2A&zoneId=all&name=Prowler%20Security%20Scanner"; + "https://dash.cloudflare.com/profile/api-tokens?permissionGroupKeys=%5B%7B%22key%22%3A%22account_settings%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22zone%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22zone_settings%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22dns%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22ssl_and_certificates%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22bot_management%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22zone_waf%22%2C%22type%22%3A%22read%22%7D%5D&accountId=%2A&zoneId=all&name=Prowler%20Security%20Scanner"; describe("CloudflareApiTokenCredentialsForm", () => { it("always renders the User API Token link with the correct href and safe target attributes", () => { diff --git a/ui/lib/external-urls.test.ts b/ui/lib/external-urls.test.ts index 86535e7794..84f7ab4d2b 100644 --- a/ui/lib/external-urls.test.ts +++ b/ui/lib/external-urls.test.ts @@ -114,20 +114,20 @@ describe("getAWSOrgDeploymentQuickLink", () => { }); describe("PRECONFIGURED_CREDENTIAL_URLS", () => { - it("keeps the Cloudflare User API Token URL under the profile route with the four required read scopes", () => { + it("keeps the Cloudflare User API Token URL under the profile route with the seven required read scopes", () => { // Snapshot check: fixes the exact URL so a stray edit to the permission // scopes, token name, account/zone selectors or console origin trips a // failing test instead of silently shipping a broken pre-configured // token flow to users. Matches the "User API Token" link in // docs/user-guide/providers/cloudflare/authentication.mdx. expect(PRECONFIGURED_CREDENTIAL_URLS.CLOUDFLARE_API_TOKEN_USER).toBe( - "https://dash.cloudflare.com/profile/api-tokens?permissionGroupKeys=%5B%7B%22key%22%3A%22account_settings%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22zone%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22zone_settings%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22dns%22%2C%22type%22%3A%22read%22%7D%5D&accountId=%2A&zoneId=all&name=Prowler%20Security%20Scanner", + "https://dash.cloudflare.com/profile/api-tokens?permissionGroupKeys=%5B%7B%22key%22%3A%22account_settings%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22zone%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22zone_settings%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22dns%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22ssl_and_certificates%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22bot_management%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22zone_waf%22%2C%22type%22%3A%22read%22%7D%5D&accountId=%2A&zoneId=all&name=Prowler%20Security%20Scanner", ); }); - it("carries the four Prowler read scopes as decoded permissionGroupKeys on the Cloudflare User API Token URL", () => { + it("carries the seven Prowler read scopes as decoded permissionGroupKeys on the Cloudflare User API Token URL", () => { // Semantic contract: the URL must request read on account_settings, zone, - // zone_settings and dns and reuse the shared Prowler token name. + // zone_settings, dns, ssl_and_certificates, bot_management and zone_waf and reuse the shared Prowler token name. const parsed = new URL( PRECONFIGURED_CREDENTIAL_URLS.CLOUDFLARE_API_TOKEN_USER, ); @@ -140,6 +140,9 @@ describe("PRECONFIGURED_CREDENTIAL_URLS", () => { { key: "zone", type: "read" }, { key: "zone_settings", type: "read" }, { key: "dns", type: "read" }, + { key: "ssl_and_certificates", type: "read" }, + { key: "bot_management", type: "read" }, + { key: "zone_waf", type: "read" }, ]); expect(parsed.searchParams.get("name")).toBe("Prowler Security Scanner"); }); @@ -214,6 +217,9 @@ describe("buildCloudflareAccountOwnedApiTokenUrl", () => { { key: "zone", type: "read" }, { key: "zone_settings", type: "read" }, { key: "dns", type: "read" }, + { key: "ssl_and_certificates", type: "read" }, + { key: "bot_management", type: "read" }, + { key: "zone_waf", type: "read" }, ]); }); diff --git a/ui/lib/external-urls.ts b/ui/lib/external-urls.ts index 10c240ba26..e8d264f70b 100644 --- a/ui/lib/external-urls.ts +++ b/ui/lib/external-urls.ts @@ -61,12 +61,13 @@ const CF_QUICKCREATE_BASE_URL = // `getAWSCredentialsTemplateLinks` below. export const PRECONFIGURED_CREDENTIAL_URLS = { // Opens the Cloudflare "Create Custom Token" form under the user profile - // pre-filled with the four read-only scopes Prowler needs - // (`Account Settings`, `Zone`, `Zone Settings`, `DNS`) and the token name. + // pre-filled with the seven read-only scopes Prowler needs (`Account + // Settings`, `Zone`, `Zone Settings`, `DNS`, `SSL and Certificates`, + // `Bot Management`, `Zone WAF`) and the token name. // Kept in sync with the "User API Token" URL published in // docs/user-guide/providers/cloudflare/authentication.mdx. CLOUDFLARE_API_TOKEN_USER: - "https://dash.cloudflare.com/profile/api-tokens?permissionGroupKeys=%5B%7B%22key%22%3A%22account_settings%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22zone%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22zone_settings%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22dns%22%2C%22type%22%3A%22read%22%7D%5D&accountId=%2A&zoneId=all&name=Prowler%20Security%20Scanner", + "https://dash.cloudflare.com/profile/api-tokens?permissionGroupKeys=%5B%7B%22key%22%3A%22account_settings%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22zone%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22zone_settings%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22dns%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22ssl_and_certificates%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22bot_management%22%2C%22type%22%3A%22read%22%7D%2C%7B%22key%22%3A%22zone_waf%22%2C%22type%22%3A%22read%22%7D%5D&accountId=%2A&zoneId=all&name=Prowler%20Security%20Scanner", // Opens the GitHub fine-grained PAT creation form pre-filled with the four // read-only permissions Prowler needs to scan a user's own repositories. // Kept in sync with the "user repositories" URL published in @@ -82,7 +83,7 @@ export const PRECONFIGURED_CREDENTIAL_URLS = { // avoid ambiguity when the user is signed into multiple accounts. Navigating // directly to `//api-tokens/create` does NOT pre-fill the form — // Cloudflare only reads the pre-fill params when they arrive via the router. -// Same four read-only scopes as the user token URL. +// Same seven read-only scopes as the user token URL. export const buildCloudflareAccountOwnedApiTokenUrl = ( accountId: string, ): string => { @@ -97,6 +98,9 @@ export const buildCloudflareAccountOwnedApiTokenUrl = ( { key: "zone", type: "read" }, { key: "zone_settings", type: "read" }, { key: "dns", type: "read" }, + { key: "ssl_and_certificates", type: "read" }, + { key: "bot_management", type: "read" }, + { key: "zone_waf", type: "read" }, ]), ); const name = encodeURIComponent("Prowler Security Scanner");