mirror of
https://github.com/prowler-cloud/prowler.git
synced 2026-10-04 02:04:06 +00:00
385 lines
13 KiB
Python
385 lines
13 KiB
Python
from datetime import timedelta
|
|
|
|
from config.custom_logging import LOGGING # noqa
|
|
from config.env import BASE_DIR, env # noqa
|
|
from config.settings.celery import * # noqa
|
|
from config.settings.eventstream import * # noqa
|
|
from config.settings.partitions import * # noqa
|
|
from config.settings.sentry import * # noqa
|
|
from config.settings.social_login import * # noqa
|
|
from django.core.exceptions import ImproperlyConfigured
|
|
|
|
SECRET_KEY = env("SECRET_KEY", default="secret")
|
|
DEBUG = env.bool("DJANGO_DEBUG", default=False)
|
|
ALLOWED_HOSTS = ["localhost", "127.0.0.1"]
|
|
SECURE_PROXY_SSL_HEADER = ("HTTP_X_FORWARDED_PROTO", "https")
|
|
USE_X_FORWARDED_HOST = True
|
|
|
|
# Application definition
|
|
|
|
INSTALLED_APPS = [
|
|
"django.contrib.admin",
|
|
"django.contrib.auth",
|
|
"django.contrib.contenttypes",
|
|
"django.contrib.sessions",
|
|
"django.contrib.messages",
|
|
"django.contrib.staticfiles",
|
|
"django.contrib.postgres",
|
|
"psqlextra",
|
|
"api",
|
|
"rest_framework",
|
|
"corsheaders",
|
|
"drf_spectacular",
|
|
"drf_spectacular_jsonapi",
|
|
"django_guid",
|
|
"rest_framework_json_api",
|
|
"django_celery_results",
|
|
"django_celery_beat",
|
|
"rest_framework_simplejwt.token_blacklist",
|
|
"allauth",
|
|
"django.contrib.sites",
|
|
"allauth.account",
|
|
"allauth.socialaccount",
|
|
"allauth.socialaccount.providers.google",
|
|
"allauth.socialaccount.providers.github",
|
|
"allauth.socialaccount.providers.saml",
|
|
"dj_rest_auth.registration",
|
|
"rest_framework.authtoken",
|
|
"drf_simple_apikey",
|
|
"django_eventstream",
|
|
]
|
|
|
|
MIDDLEWARE = [
|
|
"api.middleware.CloseDBConnectionsMiddleware",
|
|
"django_guid.middleware.guid_middleware",
|
|
"django.middleware.security.SecurityMiddleware",
|
|
"django.contrib.sessions.middleware.SessionMiddleware",
|
|
"corsheaders.middleware.CorsMiddleware",
|
|
"django.middleware.common.CommonMiddleware",
|
|
"django.middleware.csrf.CsrfViewMiddleware",
|
|
"django.contrib.auth.middleware.AuthenticationMiddleware",
|
|
"django.contrib.messages.middleware.MessageMiddleware",
|
|
"django.middleware.clickjacking.XFrameOptionsMiddleware",
|
|
"api.middleware.APILoggingMiddleware",
|
|
"allauth.account.middleware.AccountMiddleware",
|
|
]
|
|
|
|
SITE_ID = 1
|
|
|
|
CORS_ALLOWED_ORIGINS = ["http://localhost", "http://127.0.0.1"]
|
|
|
|
ROOT_URLCONF = "config.urls"
|
|
|
|
TEMPLATES = [
|
|
{
|
|
"BACKEND": "django.template.backends.django.DjangoTemplates",
|
|
"DIRS": [],
|
|
"APP_DIRS": True,
|
|
"OPTIONS": {
|
|
"context_processors": [
|
|
"django.template.context_processors.debug",
|
|
"django.template.context_processors.request",
|
|
"django.contrib.auth.context_processors.auth",
|
|
"django.contrib.messages.context_processors.messages",
|
|
],
|
|
},
|
|
},
|
|
]
|
|
|
|
REST_FRAMEWORK = {
|
|
"DEFAULT_SCHEMA_CLASS": "drf_spectacular_jsonapi.schemas.openapi.JsonApiAutoSchema",
|
|
"DEFAULT_AUTHENTICATION_CLASSES": (
|
|
"api.authentication.CombinedJWTOrAPIKeyAuthentication",
|
|
),
|
|
"PAGE_SIZE": 10,
|
|
"EXCEPTION_HANDLER": "api.exceptions.custom_exception_handler",
|
|
"DEFAULT_PAGINATION_CLASS": "drf_spectacular_jsonapi.schemas.pagination.JsonApiPageNumberPagination",
|
|
"DEFAULT_PARSER_CLASSES": (
|
|
"rest_framework_json_api.parsers.JSONParser",
|
|
"rest_framework.parsers.FormParser",
|
|
"rest_framework.parsers.MultiPartParser",
|
|
),
|
|
"DEFAULT_RENDERER_CLASSES": ("api.renderers.APIJSONRenderer",),
|
|
"DEFAULT_METADATA_CLASS": "rest_framework_json_api.metadata.JSONAPIMetadata",
|
|
"DEFAULT_FILTER_BACKENDS": (
|
|
"rest_framework_json_api.filters.QueryParameterValidationFilter",
|
|
"rest_framework_json_api.filters.OrderingFilter",
|
|
"rest_framework_json_api.django_filters.backends.DjangoFilterBackend",
|
|
"rest_framework.filters.SearchFilter",
|
|
),
|
|
"SEARCH_PARAM": "filter[search]",
|
|
"TEST_REQUEST_RENDERER_CLASSES": (
|
|
"rest_framework_json_api.renderers.JSONRenderer",
|
|
),
|
|
"TEST_REQUEST_DEFAULT_FORMAT": "vnd.api+json",
|
|
"JSON_API_UNIFORM_EXCEPTIONS": True,
|
|
"DEFAULT_THROTTLE_CLASSES": [
|
|
"rest_framework.throttling.ScopedRateThrottle",
|
|
],
|
|
"DEFAULT_THROTTLE_RATES": {
|
|
"dj_rest_auth": None,
|
|
"token-obtain": env("DJANGO_THROTTLE_TOKEN_OBTAIN", default=None),
|
|
"attack-paths-custom-query": env(
|
|
"DJANGO_THROTTLE_ATTACK_PATHS_CUSTOM_QUERY", default="10/min"
|
|
),
|
|
"health-live": env("DJANGO_THROTTLE_HEALTH_LIVE", default="120/min"),
|
|
"health-ready": env("DJANGO_THROTTLE_HEALTH_READY", default="60/min"),
|
|
},
|
|
}
|
|
|
|
SPECTACULAR_SETTINGS = {
|
|
"SERVE_INCLUDE_SCHEMA": False,
|
|
"COMPONENT_SPLIT_REQUEST": True,
|
|
"PREPROCESSING_HOOKS": [
|
|
"drf_spectacular_jsonapi.hooks.fix_nested_path_parameters",
|
|
],
|
|
"POSTPROCESSING_HOOKS": [
|
|
"api.schema_hooks.attach_task_202_examples",
|
|
],
|
|
"TITLE": "API Reference - Prowler",
|
|
}
|
|
|
|
WSGI_APPLICATION = "config.wsgi.application"
|
|
ASGI_APPLICATION = "config.asgi.application"
|
|
|
|
DJANGO_GUID = {
|
|
"GUID_HEADER_NAME": "Transaction-ID",
|
|
"VALIDATE_GUID": True,
|
|
"RETURN_HEADER": True,
|
|
"EXPOSE_HEADER": True,
|
|
"INTEGRATIONS": [],
|
|
"IGNORE_URLS": [],
|
|
"UUID_LENGTH": 32,
|
|
}
|
|
|
|
DATABASE_ROUTERS = ["api.db_router.MainRouter"]
|
|
|
|
|
|
# Password validation
|
|
# https://docs.djangoproject.com/en/5.0/ref/settings/#auth-password-validators
|
|
|
|
AUTH_USER_MODEL = "api.User"
|
|
|
|
AUTH_PASSWORD_VALIDATORS = [
|
|
{
|
|
"NAME": "django.contrib.auth.password_validation.UserAttributeSimilarityValidator",
|
|
},
|
|
{
|
|
"NAME": "django.contrib.auth.password_validation.MinimumLengthValidator",
|
|
"OPTIONS": {"min_length": 12},
|
|
},
|
|
{
|
|
"NAME": "api.validators.MaximumLengthValidator",
|
|
"OPTIONS": {
|
|
"max_length": 72,
|
|
},
|
|
},
|
|
{
|
|
"NAME": "django.contrib.auth.password_validation.CommonPasswordValidator",
|
|
},
|
|
{
|
|
"NAME": "django.contrib.auth.password_validation.NumericPasswordValidator",
|
|
},
|
|
{
|
|
"NAME": "api.validators.SpecialCharactersValidator",
|
|
"OPTIONS": {
|
|
"min_special_characters": 1,
|
|
},
|
|
},
|
|
{
|
|
"NAME": "api.validators.UppercaseValidator",
|
|
"OPTIONS": {
|
|
"min_uppercase": 1,
|
|
},
|
|
},
|
|
{
|
|
"NAME": "api.validators.LowercaseValidator",
|
|
"OPTIONS": {
|
|
"min_lowercase": 1,
|
|
},
|
|
},
|
|
{
|
|
"NAME": "api.validators.NumericValidator",
|
|
"OPTIONS": {
|
|
"min_numeric": 1,
|
|
},
|
|
},
|
|
]
|
|
|
|
SIMPLE_JWT = {
|
|
# Token lifetime settings
|
|
"ACCESS_TOKEN_LIFETIME": timedelta(
|
|
minutes=env.int("DJANGO_ACCESS_TOKEN_LIFETIME", 30)
|
|
),
|
|
"REFRESH_TOKEN_LIFETIME": timedelta(
|
|
minutes=env.int("DJANGO_REFRESH_TOKEN_LIFETIME", 60 * 24)
|
|
),
|
|
"ROTATE_REFRESH_TOKENS": True,
|
|
"BLACKLIST_AFTER_ROTATION": True,
|
|
# Algorithm and keys
|
|
"ALGORITHM": "RS256",
|
|
"SIGNING_KEY": env.str("DJANGO_TOKEN_SIGNING_KEY", "").replace("\\n", "\n"),
|
|
"VERIFYING_KEY": env.str("DJANGO_TOKEN_VERIFYING_KEY", "").replace("\\n", "\n"),
|
|
# Authorization header configuration
|
|
"AUTH_HEADER_TYPES": ("Bearer",),
|
|
"AUTH_HEADER_NAME": "HTTP_AUTHORIZATION",
|
|
# Custom serializers
|
|
"TOKEN_OBTAIN_SERIALIZER": "api.serializers.TokenSerializer",
|
|
"TOKEN_REFRESH_SERIALIZER": "api.serializers.TokenRefreshSerializer",
|
|
# Standard JWT claims
|
|
"TOKEN_TYPE_CLAIM": "typ",
|
|
"JTI_CLAIM": "jti",
|
|
"USER_ID_FIELD": "id",
|
|
"USER_ID_CLAIM": "sub",
|
|
"CHECK_REVOKE_TOKEN": True,
|
|
# Issuer and Audience claims, for the moment we will keep these values as default values, they may change in the
|
|
# future.
|
|
"AUDIENCE": env.str("DJANGO_JWT_AUDIENCE", "https://api.prowler.com"),
|
|
"ISSUER": env.str("DJANGO_JWT_ISSUER", "https://api.prowler.com"),
|
|
# Additional security settings
|
|
"UPDATE_LAST_LOGIN": True,
|
|
}
|
|
|
|
SECRETS_ENCRYPTION_KEY = env.str("DJANGO_SECRETS_ENCRYPTION_KEY", "")
|
|
|
|
# DRF Simple API Key settings
|
|
DRF_API_KEY = {
|
|
"FERNET_SECRET": SECRETS_ENCRYPTION_KEY,
|
|
"API_KEY_LIFETIME": 365,
|
|
"AUTHENTICATION_KEYWORD_HEADER": "Api-Key",
|
|
}
|
|
|
|
# Internationalization
|
|
# https://docs.djangoproject.com/en/5.0/topics/i18n/
|
|
|
|
LANGUAGE_CODE = "en-us"
|
|
LANGUAGES = [
|
|
("en", "English"),
|
|
]
|
|
|
|
TIME_ZONE = "UTC"
|
|
|
|
USE_I18N = True
|
|
|
|
USE_TZ = True
|
|
|
|
# Static files (CSS, JavaScript, Images)
|
|
# https://docs.djangoproject.com/en/5.0/howto/static-files/
|
|
|
|
STATIC_URL = "static/"
|
|
|
|
# Default primary key field type
|
|
# https://docs.djangoproject.com/en/5.0/ref/settings/#default-auto-field
|
|
|
|
DEFAULT_AUTO_FIELD = "django.db.models.BigAutoField"
|
|
|
|
# Cache settings
|
|
CACHE_MAX_AGE = env.int("DJANGO_CACHE_MAX_AGE", 3600)
|
|
CACHE_STALE_WHILE_REVALIDATE = env.int("DJANGO_STALE_WHILE_REVALIDATE", 60)
|
|
|
|
|
|
TESTING = False
|
|
|
|
FINDINGS_MAX_DAYS_IN_RANGE = env.int("DJANGO_FINDINGS_MAX_DAYS_IN_RANGE", 7)
|
|
|
|
|
|
# API export settings
|
|
DJANGO_TMP_OUTPUT_DIRECTORY = env.str(
|
|
"DJANGO_TMP_OUTPUT_DIRECTORY", "/tmp/prowler_api_output"
|
|
)
|
|
DJANGO_FINDINGS_BATCH_SIZE = env.int("DJANGO_FINDINGS_BATCH_SIZE", 1000)
|
|
|
|
DJANGO_OUTPUT_S3_AWS_OUTPUT_BUCKET = env.str("DJANGO_OUTPUT_S3_AWS_OUTPUT_BUCKET", "")
|
|
DJANGO_OUTPUT_S3_AWS_ACCESS_KEY_ID = env.str("DJANGO_OUTPUT_S3_AWS_ACCESS_KEY_ID", "")
|
|
DJANGO_OUTPUT_S3_AWS_SECRET_ACCESS_KEY = env.str(
|
|
"DJANGO_OUTPUT_S3_AWS_SECRET_ACCESS_KEY", ""
|
|
)
|
|
DJANGO_OUTPUT_S3_AWS_SESSION_TOKEN = env.str("DJANGO_OUTPUT_S3_AWS_SESSION_TOKEN", "")
|
|
DJANGO_OUTPUT_S3_AWS_DEFAULT_REGION = env.str("DJANGO_OUTPUT_S3_AWS_DEFAULT_REGION", "")
|
|
# Storage endpoint the API and Celery workers use to talk to S3-compatible object storage
|
|
# such as MinIO. Empty means the real AWS S3 endpoint, which is unaffected.
|
|
DJANGO_OUTPUT_S3_AWS_ENDPOINT_URL = env.str("DJANGO_OUTPUT_S3_AWS_ENDPOINT_URL", "")
|
|
# Browser-reachable storage host used to sign download URLs. Empty means sign against the
|
|
# same endpoint the API talks to, which is what Prowler Cloud on S3 does.
|
|
DJANGO_OUTPUT_S3_AWS_PUBLIC_ENDPOINT_URL = env.str(
|
|
"DJANGO_OUTPUT_S3_AWS_PUBLIC_ENDPOINT_URL", ""
|
|
)
|
|
|
|
# HTTP Security Headers
|
|
SECURE_CONTENT_TYPE_NOSNIFF = True
|
|
X_FRAME_OPTIONS = "DENY"
|
|
SECURE_REFERRER_POLICY = "strict-origin-when-cross-origin"
|
|
|
|
DJANGO_DELETION_BATCH_SIZE = env.int("DJANGO_DELETION_BATCH_SIZE", 5000)
|
|
|
|
# Public base URL of the Prowler UI (for example https://cloud.prowler.com). Used to
|
|
# build links back to findings in outbound integrations such as Jira. Empty by
|
|
# default, so self-hosted deployments emit no links unless they configure it.
|
|
UI_BASE_URL = env.str("DJANGO_UI_BASE_URL", "").rstrip("/")
|
|
|
|
# SAML requirement
|
|
CSRF_COOKIE_SECURE = True
|
|
SESSION_COOKIE_SECURE = True
|
|
|
|
# Attack Paths
|
|
ATTACK_PATHS_SCAN_INACTIVITY_THRESHOLD_MINUTES = env.int(
|
|
"ATTACK_PATHS_SCAN_INACTIVITY_THRESHOLD_MINUTES", 30
|
|
)
|
|
ATTACK_PATHS_SCAN_STALE_THRESHOLD_MINUTES = env.int(
|
|
"ATTACK_PATHS_SCAN_STALE_THRESHOLD_MINUTES", 960
|
|
) # 16h
|
|
|
|
# Minimum age (of the scan row, or of the scan id itself when the row is gone) before
|
|
# the periodic reaper will drop an orphaned temp Neo4j database. Keeps a scan that is
|
|
# still legitimately in flight from ever losing its staging database mid-run.
|
|
ATTACK_PATHS_TMP_DB_REAP_SAFETY_MARGIN_HOURS = env.int(
|
|
"ATTACK_PATHS_TMP_DB_REAP_SAFETY_MARGIN_HOURS", 6
|
|
)
|
|
if ATTACK_PATHS_TMP_DB_REAP_SAFETY_MARGIN_HOURS <= 0:
|
|
raise ImproperlyConfigured(
|
|
"ATTACK_PATHS_TMP_DB_REAP_SAFETY_MARGIN_HOURS must be a positive number of hours"
|
|
)
|
|
|
|
# Selects where the persistent attack-paths graph is stored. The scan
|
|
# temporary database is always Neo4j; only the sink is configurable.
|
|
# Valid values: "neo4j" (default, OSS and local dev), "neptune" (hosted).
|
|
ATTACK_PATHS_SINK_DATABASE = env.str("ATTACK_PATHS_SINK_DATABASE", default="neo4j")
|
|
|
|
# Lighthouse AI
|
|
# Comma-separated hostnames (or IP literals) that bypass the SSRF validation
|
|
# applied to OpenAI-compatible provider base URLs, so self-hosted deployments
|
|
# can point Lighthouse AI at internal endpoints. Empty by default: every base
|
|
# URL must resolve to a public endpoint.
|
|
LIGHTHOUSE_AI_OPENAI_COMPATIBLE_ALLOWED_HOSTS = env.list(
|
|
"LIGHTHOUSE_AI_OPENAI_COMPATIBLE_ALLOWED_HOSTS", default=[]
|
|
)
|
|
|
|
# Orphan task recovery feature flags. The master switch is OFF by default, so task
|
|
# recovery is opt-in; enable it with DJANGO_TASK_RECOVERY_ENABLED=true. The per-group
|
|
# toggles default to enabled, so once the master is on every group recovers unless a
|
|
# group is explicitly turned off.
|
|
TASK_RECOVERY_ENABLED = env.bool("DJANGO_TASK_RECOVERY_ENABLED", False)
|
|
TASK_RECOVERY_SUMMARIES_ENABLED = env.bool(
|
|
"DJANGO_TASK_RECOVERY_SUMMARIES_ENABLED", True
|
|
)
|
|
TASK_RECOVERY_DELETIONS_ENABLED = env.bool(
|
|
"DJANGO_TASK_RECOVERY_DELETIONS_ENABLED", True
|
|
)
|
|
|
|
|
|
def label_postgres_connections(databases):
|
|
"""Tag each Postgres connection with ``application_name="<component>:<alias>"``
|
|
so connections are attributable by component in ``pg_stat_activity`` (and any
|
|
tooling that surfaces ``application_name``). The component (api / worker /
|
|
scan / ...) is injected per process by the container entrypoint via
|
|
``DJANGO_APP_COMPONENT``; the alias distinguishes which pool inside the
|
|
process owns the connection. The neo4j entry is skipped (not a Postgres
|
|
backend). Postgres truncates ``application_name`` at 63 bytes.
|
|
"""
|
|
component = env.str("DJANGO_APP_COMPONENT", default="api")
|
|
for alias, config in databases.items():
|
|
engine = config.get("ENGINE", "")
|
|
if engine.startswith("psqlextra") or "postgresql" in engine:
|
|
name = f"{component}:{alias}"[:63]
|
|
config.setdefault("OPTIONS", {})["application_name"] = name
|