GithubHelp home page GithubHelp logo

hxsecurity / dongtai-webapi Goto Github PK

View Code? Open in Web Editor NEW
8.0 13.0 19.0 8.05 MB

DongTai-WebAPI is the server part of the management tool of DongTai-IAST

License: Apache License 2.0

Dockerfile 0.12% Python 96.58% Shell 1.82% Batchfile 1.48%
dongtai dongtai-iast django security appsec iast django-rest-framework

dongtai-webapi's People

Contributors

bidaya0 avatar dependabot[bot] avatar exexute avatar hardy4yooz avatar jinghao1 avatar quantyork avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

dongtai-webapi's Issues

[Bug]: Fix the program error when there is a null value

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.
  • I am not looking for support or already pursued the available support channels without success.

Version

1.1.0

Installation Type

Official SaaS Service

Service Name

DongTai-WebAPI

Describe the details of the bug and the steps to reproduce it

image

Additional Information

No response

Logs

No response

github被墙导致代码拉不下来

问题:
由于国内的网络问题,git被墙拉不下来代码,本地部署难度增高;

解决方案:
上传构建好的镜像到公共镜像服务,供社区下载试用

[Bug]: /api/v1/vulns local variable 'result' referenced before assignment

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.
  • I am not looking for support or already pursued the available support channels without success.

Version

1.1.3

Installation Type

Official SaaS Service

Service Name

DongTai-WebAPI

Describe the details of the bug and the steps to reproduce it

image

Additional Information

No response

Logs

No response

[Bug]: Inconsistent statistics due to multiple versions of the project

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.
  • I am not looking for support or already pursued the available support channels without success.

Version

1.1.0

Installation Type

Official SaaS Service

Service Name

DongTai-WebAPI

Describe the details of the bug and the steps to reproduce it

Inconsistent statistics due to multiple versions of the project.
image
image

Additional Information

No response

Logs

No response

[Bug]: Vulnerability type merge error with the same name

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.
  • I am not looking for support or already pursued the available support channels without success.

Version

1.1.2

Installation Type

Official Docker Compose

Service Name

DongTai-WebAPI

Describe the details of the bug and the steps to reproduce it

image

Additional Information

No response

Logs

No response

[Bug]: status mapping incorrect

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.
  • I am not looking for support or already pursued the available support channels without success.

Version

1.1.2

Installation Type

Official SaaS Service

Service Name

DongTai-WebAPI

Describe the details of the bug and the steps to reproduce it

HXSecurity/DongTai#358

Additional Information

No response

Logs

No response

[Feature]: Merged the openapi address settings registered by the service, changed to dongtai-web nginx forwarding

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.

Problem Description

  • The back-end service accesses openapi through the intranet alias

Proposed Solution

  • The back-end service accesses openapi through the intranet alias

Alternatives Considered

No response

Additional Information

No response

[Bug]: Incorrect permissions for sensitive information

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.
  • I am not looking for support or already pursued the available support channels without success.

Version

1.1.2

Installation Type

Official Docker Compose

Service Name

DongTai-WebAPI

Describe the details of the bug and the steps to reproduce it

image

Additional Information

No response

Logs

No response

[Bug]: Verification of agent_id during project creation may cause errors

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.
  • I am not looking for support or already pursued the available support channels without success.

Version

1.1.2

Installation Type

Official Docker Compose

Service Name

DongTai-WebAPI

Describe the details of the bug and the steps to reproduce it

Verification of agent_id during project creation may cause errors

Additional Information

image

Logs

No response

[Bug]: VulSummary Inappropriate sql query causes API timeout

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.
  • I am not looking for support or already pursued the available support channels without success.

Version

1.1.3

Installation Type

Official SaaS Service

Service Name

DongTai-WebAPI

Describe the details of the bug and the steps to reproduce it

VulSummary Inappropriate sql query causes API timeout
20211213-152457

Additional Information

No response

Logs

No response

[Bug]: The corresponding strategy was not created at the same time when the dangerous rule was created

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.
  • I am not looking for support or already pursued the available support channels without success.

Version

1.1.0

Installation Type

Official SaaS Service

Service Name

DongTai-WebAPI

Describe the details of the bug and the steps to reproduce it

The corresponding strategy was not created at the same time when the dangerous rule was created

Additional Information

solution

  • When creating a strategy, create the corresponding risk type and filter type at the same time
  • Remove the interface for creating dangerous types and filtering types

Logs

No response

[Feature]: Project adds vulnerability verification switch

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.

Problem Description

  • Project adds vulnerability verification switch

Proposed Solution

  • Added vulnerability verification switch field

Alternatives Considered

No response

Additional Information

No response

[Bug]: Unreasonable escaping causes the text to display incorrectly

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.
  • I am not looking for support or already pursued the available support channels without success.

Version

1.1.0

Installation Type

Official SaaS Service

Service Name

DongTai-WebAPI

Describe the details of the bug and the steps to reproduce it

Unreasonable escaping causes the text to display incorrectly

Additional Information

No response

Logs

No response

[Feature]: Sensitive information rule configuration

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.

Problem Description

  • Sensitive information rule configuration

Proposed Solution

  • Add API for obtaining sensitive information rule list
  • Added new sensitive information rule API
  • Add sensitive information rule status modification API
  • Add sensitive information rule editing API
  • Add sensitive information rule deleted API
  • Add sensitive information pattern type list API

Noted:

  • When policy created, the corresponding sensitive information type are automatically created
  • When modifying the name, modify the corresponding type at the same time
  • When creating a rule, at the same time check whether the rule conforms to the type it belongs to, for example, check whether the regex conforms to REGEX POSIX 1003.2
  • When deleting a rule, only the status bit of the rule is modified without actually deleting the data

Alternatives Considered

Additional Information

No response

[Feature]: Adjust the structure to facilitate development and expansion

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.

Problem Description

The amount of code is too much, there is no reasonable modularization, it is difficult to expand and secondary development

Proposed Solution

  • Split the logic of importing the app
  • Establish a patch mechanism to modify the existing code according to the version

Alternatives Considered

No response

Additional Information

No response

[Bug]: When adding items, the operation is non-atomic, and an error occurs but partially saved

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.
  • I am not looking for support or already pursued the available support channels without success.

Version

1.1.2

Installation Type

Official Docker Compose

Service Name

DongTai-WebAPI

Describe the details of the bug and the steps to reproduce it

When adding items, the operation is non-atomic, and an error occurs but partially saved

Additional Information

No response

Logs

No response

[Feature]: In some interfaces, the detail field of the list is inconsistent with the detail field

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.

Problem Description

In some interfaces, the detail field of the list is inconsistent with the detail field
For example:
1640326305(1)
This leads to some difficulties in coupling Dongtai to other systems

Proposed Solution

Uniform field

Alternatives Considered

No response

Additional Information

No response

[Bug]: The name of the scanning strategy is not brought back when returning

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.
  • I am not looking for support or already pursued the available support channels without success.

Version

1.1.3

Installation Type

Official SaaS Service

Service Name

DongTai-WebAPI

Describe the details of the bug and the steps to reproduce it

image

Additional Information

No response

Logs

No response

[Feature]: Change the status of custom rules in bulk

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.

Problem Description

Administrators need to manage custom rules in batches

Proposed Solution

Add api to change the status of custom rules in bulk

Alternatives Considered

No response

Additional Information

No response

[Feature]: Add some interface support get detail with id list

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.

Problem Description

Add some interface support get detail with id list,for example,

get project list with id list
get agent list with id list
get sca list with id list
...

Proposed Solution

Add some interface support get detail with id list,for example,

get project list with id list
get agent list with id list
get sca list with id list
...

Alternatives Considered

No response

Additional Information

No response

http请求头数据base64解码失败

测试数据

aG9zdDpsb2NhbGhvc3Q6ODA4MApjb25uZWN0aW9uOmtlZXAtYWxpdmUKc2VjLWNoLXVhOiIgTm90
IEE7QnJhbmQiO3Y9Ijk5IiwgIkNocm9taXVtIjt2PSI5MCIsICJHb29nbGUgQ2hyb21lIjt2PSI5
MCIKc2VjLWNoLXVhLW1vYmlsZTo/MAp1cGdyYWRlLWluc2VjdXJlLXJlcXVlc3RzOjEKdXNlci1h
Z2VudDpNb3ppbGxhLzUuMCAoV2luZG93cyBOVCAxMC4wOyBXaW42NDsgeDY0KSBBcHBsZVdlYktp
dC81MzcuMzYgKEtIVE1MLCBsaWtlIEdlY2tvKSBDaHJvbWUvOTAuMC40NDMwLjIxMiBTYWZhcmkv
NTM3LjM2CmFjY2VwdDp0ZXh0L2h0bWwsYXBwbGljYXRpb24veGh0bWwreG1sLGFwcGxpY2F0aW9u
L3htbDtxPTAuOSxpbWFnZS9hdmlmLGltYWdlL3dlYnAsaW1hZ2UvYXBuZywqLyo7cT0wLjgsYXBw
bGljYXRpb24vc2lnbmVkLWV4Y2hhbmdlO3Y9YjM7cT0wLjkKc2VjLWZldGNoLXNpdGU6c2FtZS1v
cmlnaW4Kc2VjLWZldGNoLW1vZGU6bmF2aWdhdGUKc2VjLWZldGNoLXVzZXI6PzEKc2VjLWZldGNo
LWRlc3Q6ZG9jdW1lbnQKcmVmZXJlcjpodHRwOi8vbG9jYWxob3N0OjgwODAvdnVsbnMvMDIxLW5p
by1maWxlLmpzcAphY2NlcHQtZW5jb2Rpbmc6Z3ppcCwgZGVmbGF0ZSwgYnIKYWNjZXB0LWxhbmd1
YWdlOnpoLUNOLHpoO3E9MC45CmNvb2tpZTpKU0VTU0lPTklEPTZBRUI4NEM4NTM4MzNGNDg1REEx
RDhDNDVDRjVFNjQwOyByZW1lbWJlck1lPTlMampKU1RXZVZDMFMzVm53S3Q1WTRBUkhSaEo0ZndS
SS9ZRituMVlqN2kzYzBJVlRlTGJteTFvOXE2a1VZQit0eDhyRlhNaTRhTEgvNnNJUzVyWURVczhM
enZjUVhSQ0RRcDI0UnR5K2pWN3dMSU9KejI3dm1DemFqbnFaaVNCSTAvQXdnR1VIZG8xWGV6TlU3
OTRheTM5aGl4SmdxWGN4WnRma1pCNFl4bFFUNDQvazlvakR1dWs1YXZDR3lDV3VPODZUSEg5aVlI
ZGozNkc1SWYwN2JOUksyNW1hNVVYeXpVL3RPcktwSmhOMHFBbXExRjRwaTA4OWpQYWRrSkV0WEZw
TWV0eCtRanJPSmJJTksrN2pLTjlEaGtQVFdEMitlT3pEWEFvMEp2cG51Qlk2UzBaNGlCeVROWGRF
MmVwVEh4N3NnamRpcXo2L3dwTW5NNU9aSTFDbFVnSGpEMHBZTWsxdjNxbGN3STVSNjZXbjFIc1lC
QThMZGVqQzAzeGlvVEhDT3dmK21FZG42UjZBUEtpMDYveVIxdnB6TXcvazhMTW43c3RCY2RSZW12
OGxtUVRrY0s4dUFRYXlyREdKRkUwN2liN1ZnRk1HaGJPcXllcVlueWtzTng5UVJxY25WNkl5MTVU
V2N3bTlPR1FIaU1Fc28xeWx5VElXMU13ZXVCSzBQcHI5SGJBYlJFVXBVYm94THRNSjQyeE1xdHZs
MjArS1FKSU9qSVUrVzcyV3crRVRjOVFVbkRHQ0lxcUI0V2lvTlhid0E4aktaaG84VmNJeDNsS3Nn
RnpPYzJhQ1B3TytldGFvRlM0ZEpMbm1CTjVmVDdLTHpXOEdtVFB6bGhFWURjSmtIZXQ3N1dOZjQw
OFhDY3VVT0pXc2RYNGJnTGpJVmRTdDRtOFJ2bVVaVDJqamFneXN0ODlUNHNBTElaOER0N0ZaZUZ4
clZvQUtBclNGaHRHMFlVQmVpTDFXL1I3L2ZVa25nRHdaZ0dDTVBGbFNtRHhTOC9RcHUzVzdTR2x

Base64 Decode实现

import base64

header = """xxxx
xxxx
"""
base64.b64decode(header.encode("utf-8")).decode("utf-8")

[Feature]: Hook rule modification

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.

Problem Description

Remove the entry of filter rules and dangerous rules, which are created when the policy is created.

Proposed Solution

Remove the entry of filter rules and dangerous rules, which are created when the policy is created.

Alternatives Considered

No response

Additional Information

No response

[Bug]: /api/v1/sensitive_info_rule/ fields No indication of range

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.
  • I am not looking for support or already pursued the available support channels without success.

Version

1.1.3

Installation Type

Official SaaS Service

Service Name

DongTai-WebAPI

Describe the details of the bug and the steps to reproduce it

image
image

Additional Information

No response

Logs

No response

[Feature]: Strategic part modification

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.

Problem Description

The management interface lacks the ability to create a new strategy

problem:
After adding the sensitive information function, from how to distribute the new policy to the hook rule or the sensitive information rule, or to display them in the newly created hook rule and the sensitive rule at the same time, and distribute it by creating specific rules
Noted:
When policy created, the corresponding sensitive information type are automatically created

Proposed Solution

  • Add strategy add interface

Alternatives Considered

No response

Additional Information

No response

[Bug]: The hook type cannot be changed

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.
  • I am not looking for support or already pursued the available support channels without success.

Version

1.1.2

Installation Type

Official Docker Compose

Service Name

DongTai-WebAPI

Describe the details of the bug and the steps to reproduce it

HXSecurity/DongTai#357

Additional Information

No response

Logs

No response

[Bug]: /api/v1/vuln/summary Failure to properly handle database out of synchronization with agent language

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.
  • I am not looking for support or already pursued the available support channels without success.

Version

1.1.3

Installation Type

Official SaaS Service

Service Name

DongTai-WebAPI

Describe the details of the bug and the steps to reproduce it

KeyError at /api/v1/vuln/summary
'GO'

Request Method: GET
Request URL: https://dongtai-webapi-svc/api/v1/vuln/summary?language=&level=&type=&project_name=&url=&order=&status_id=&project_id=
Django Version: 3.0.3
Python Executable: /usr/local/bin/uwsgi
Python Version: 3.7.7
Python Path: ['.', '', '/usr/local/lib/python37.zip', '/usr/local/lib/python3.7', '/usr/local/lib/python3.7/lib-dynload', '/usr/local/lib/python3.7/site-packages']
Server time: Wed, 8 Dec 2021 12:12:19 +0800

Additional Information

No response

Logs

No response

[Feature]: The project list needs to be sorted according to the time of the update related vulnerabilities or component information

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.

Problem Description

The existing sorting is sorted according to the modification project setting time.

Proposed Solution

  • Option One:
    WebApi calculates the vulnerability or component data recently acquired by the project when viewing the project list
    The update time is used as a calculated attribute.
    Pro:
    The area of the change is smaller and will not be affected by the agent-related data, such as deleting the agent and replacing the agent
    Con:
    Increase the query time of this interface of webapi

  • Option II:
    OpenApi processes the update time of the project while receiving the reported data
    The update time is used as a storage attributes.
    Pro:
    Compared with solution 1, the time impact on the user side is less.
    Con:
    The field used to store item attribute changes is invalid.

Alternatives Considered

No response

Additional Information

No response

[Feature]: Scan policy template management

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.

Problem Description

Existing scan policy templates can only be created and queried, but cannot be modified or deleted.

Proposed Solution

Specific work:

  • Add a single strategy acquisition interface
  • The existing list interface adds functions such as search and sorting
  • Configure the corresponding permission policy
  • Increase deletion, consider whether to adopt false deletion
  • Add modify interface

Points to consider:

  • Existing queries and additions are available to each user, and policy changes may require changes to existing business logic
  • Existing new creation is also available for all users
  • Need to consider existing interactions after new permission settings
  • When the scanning strategy is deleted, how to deal with the items that select the strategy

Alternatives Considered

No response

Additional Information

No response

[Bug]: Cookie failure after changing the password causes 403 logout

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.
  • I am not looking for support or already pursued the available support channels without success.

Version

1.1.3

Installation Type

Official SaaS Service

Service Name

DongTai-WebAPI

Describe the details of the bug and the steps to reproduce it

  1. change the password
  2. change success
  3. redriect to default page
  4. 403

Additional Information

No response

Logs

No response

[Bug]: not enough values to unpack (expected 6, got 5)

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.
  • I am not looking for support or already pursued the available support channels without success.

Version

1.1.2

Installation Type

Official Docker Compose

Service Name

DongTai-WebAPI

Describe the details of the bug and the steps to reproduce it

image

Additional Information

No response

Logs

No response

[Bug]: Failed to add strategy, vul_fix cannot be empty

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.
  • I am not looking for support or already pursued the available support channels without success.

Version

1.1.2

Installation Type

Official SaaS Service

Service Name

DongTai-WebAPI

Describe the details of the bug and the steps to reproduce it

image

Additional Information

No response

Logs

No response

[Bug]: history_data vul detected missing after vul_type modify

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.
  • I am not looking for support or already pursued the available support channels without success.

Version

1.1.4

Installation Type

Official Docker Compose

Service Name

DongTai-WebAPI

Describe the details of the bug and the steps to reproduce it

history_data vul detected missing after vul_type modify

Additional Information

No response

Logs

No response

[Bug]: /api/v1/engine/request/replay GET this API has a disemancy field

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.
  • I am not looking for support or already pursued the available support channels without success.

Version

1.1.2

Installation Type

Official SaaS Service

Service Name

DongTai-WebAPI

Describe the details of the bug and the steps to reproduce it

this API has a disemancy field.
Causes the following problems:
The client mishandled the replay type for which the return field was returned

Additional Information

No response

Logs

No response

[Bug]: VulDetail when container is None , argument of type 'NoneType' is not iterable

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.
  • I am not looking for support or already pursued the available support channels without success.

Version

1.1.3

Installation Type

Official SaaS Service

Service Name

DongTai-WebAPI

Describe the details of the bug and the steps to reproduce it

Uploading image.png…

Additional Information

No response

Logs

No response

[Bug]: The corresponding strategy was not created at the same time when the dangerous rule was created

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.
  • I am not looking for support or already pursued the available support channels without success.

Version

1.1.0

Installation Type

Official SaaS Service

Service Name

DongTai-WebAPI

Describe the details of the bug and the steps to reproduce it

  • add the corresponding creation strategy logic

Additional Information

No response

Logs

No response

性能优化

随着数据量的增加,性能问题逐渐出来,需要进行优化

[Bug]: Hook type add error

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.
  • I am not looking for support or already pursued the available support channels without success.

Version

1.1.2

Installation Type

Official Docker Compose

Service Name

DongTai-WebAPI

Describe the details of the bug and the steps to reproduce it

image

Additional Information

No response

Logs

No response

[Bug]: Adding items may cause scan_id to be empty

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.
  • I am not looking for support or already pursued the available support channels without success.

Version

1.1.2

Installation Type

Official SaaS Service

Service Name

DongTai-WebAPI

Describe the details of the bug and the steps to reproduce it

  • When adding a policy, there is no check for the existence of the scanning policy
  • Empty when scanning strategy does not exist

Additional Information

No response

Logs

No response

[Enhancement]: Component summary query time is too long

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.
  • I am not looking for support or already pursued the available support channels without success.

Version

1.1.4

Installation Type

Official SaaS Service

Service Name

DongTai-WebAPI

Describe the details of the bug and the steps to reproduce it

image

Additional Information

No response

Logs

No response

[Feature]: Increase the type of hard-coded vulnerabilities

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.

Problem Description

Increase the type of hard-coded vulnerabilities

Proposed Solution

Increase the type of hard-coded vulnerabilities

Alternatives Considered

No response

Additional Information

No response

[Feature]: Component list, add the path where the component is located

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.

Problem Description

The existing component list is missing component path information.

Proposed Solution

Add component path when displaying

  • Asset.package_path

Alternatives Considered

No response

Additional Information

No response

[Bug]: vul_recheck not working

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.
  • I am not looking for support or already pursued the available support channels without success.

Version

1.1.0

Installation Type

Official SaaS Service

Service Name

DongTai-WebAPI

Describe the details of the bug and the steps to reproduce it

  1. The status of the replay settings is incorrect
  2. Unhandled exception in query during batch replay

Additional Information

No response

Logs

No response

[Feature]: The data fields of the interface can be improved

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.

Problem Description

The agent information in the project agent and project details interface can only return an ID field, and the details can be loaded through the agent interface

Proposed Solution

The agent information in the project agent and project details interface can only return an ID field, and the details can be loaded through the agent interface

Alternatives Considered

No response

Additional Information

No response

[Bug]: CSRF Failed: Referer checking failed - https://dev-iast.huoxian.cn:1024/taint/search does not match any trusted origins.

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.
  • I am not looking for support or already pursued the available support channels without success.

Version

1.1.0

Installation Type

Official SaaS Service

Service Name

DongTai-WebAPI

Describe the details of the bug and the steps to reproduce it

CSRF Failed: Referer checking failed - https://dev-iast.huoxian.cn:1024/taint/search does not match any trusted origins.

Additional Information

No response

Logs

No response

[Feature]: Modify the default testrunner of django and add a regression test process

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.

Problem Description

Modify the default testrunner of django and add a regression test process

Proposed Solution

  • Modify the default testrunner
  • Add regression tests to fixed bugs

Alternatives Considered

No response

Additional Information

No response

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.