mirror of
https://github.com/prowler-cloud/prowler.git
synced 2026-10-09 21:14:22 +00:00
fix(openstack): validate auth_url before the SDK connects
This commit is contained in:
4 files changed
+32
-3
No files matched your search
@@ -1 +1 @@
|
||||
OpenStack connection test rejects an `auth_url` with a non-HTTP scheme or a host that resolves to a loopback, link-local or private address, so a tenant-supplied clouds.yaml can no longer make the worker probe internal services
|
||||
OpenStack auth_url resolving to loopback, private or otherwise non-public hosts rejected before the SDK connects, on both the connection test and the scan
|
||||
@@ -482,6 +482,7 @@ class OpenstackProvider(Provider):
|
||||
region: Optional region override — when given, the connection is
|
||||
scoped to this specific region instead of the session default.
|
||||
"""
|
||||
OpenstackProvider._validate_auth_url(session.auth_url)
|
||||
try:
|
||||
# Don't load from clouds.yaml or environment variables, we configure this in setup_session()
|
||||
conn = connect(
|
||||
@@ -628,8 +629,6 @@ class OpenstackProvider(Provider):
|
||||
project_domain_name=project_domain_name,
|
||||
)
|
||||
|
||||
OpenstackProvider._validate_auth_url(session.auth_url)
|
||||
|
||||
# Validate provider_id matches project_id from config
|
||||
if provider_id and session.project_id != provider_id:
|
||||
raise OpenStackInvalidProviderIdError(
|
||||
|
||||
Whitespace-only changes.
@@ -1727,6 +1727,36 @@ clouds:
|
||||
raise_on_exception=True,
|
||||
)
|
||||
|
||||
def test_scan_initialisation_rejects_a_non_public_auth_url(self):
|
||||
with patch(
|
||||
"prowler.providers.openstack.openstack_provider.connect"
|
||||
) as mock_connect:
|
||||
with pytest.raises(OpenStackAuthUrlNotAllowedError):
|
||||
OpenstackProvider(
|
||||
auth_url="https://169.254.169.254:5000/v3",
|
||||
username="test-user",
|
||||
password="test-password",
|
||||
project_id="test-project-id",
|
||||
region_name="RegionOne",
|
||||
)
|
||||
|
||||
mock_connect.assert_not_called()
|
||||
|
||||
def test_scan_initialisation_rejects_shared_address_space(self):
|
||||
with patch(
|
||||
"prowler.providers.openstack.openstack_provider.connect"
|
||||
) as mock_connect:
|
||||
with pytest.raises(OpenStackAuthUrlNotAllowedError):
|
||||
OpenstackProvider(
|
||||
auth_url="https://100.100.100.200:5000/v3",
|
||||
username="test-user",
|
||||
password="test-password",
|
||||
project_id="test-project-id",
|
||||
region_name="RegionOne",
|
||||
)
|
||||
|
||||
mock_connect.assert_not_called()
|
||||
|
||||
def test_test_connection_allows_public_auth_url(self):
|
||||
result, mock_connect = self._test_connection(
|
||||
auth_url="https://openstack.example.com:5000/v3"
|
||||
|
||||
Reference in new issue
Block a user