-
Notifications
You must be signed in to change notification settings - Fork 1.1k
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
fix(openapi): Fix CKV_OpenAPI_20 (#5302)
Fix CKV_OpenAPI_20
- Loading branch information
Showing
10 changed files
with
330 additions
and
0 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
42 changes: 42 additions & 0 deletions
42
tests/openapi/checks/resource/generic/example_ClearTextAPIKey/fail3.json
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,42 @@ | ||
{ | ||
"swagger": "2.0", | ||
"info": { | ||
"title": "Simple API overview", | ||
"version": "1.0.0" | ||
}, | ||
"schemes": [ | ||
"https", | ||
"http" | ||
], | ||
"paths": { | ||
"/pets": { | ||
"post": { | ||
"description": "Creates a new pet in the store", | ||
"responses": { | ||
"200": { | ||
"description": "200 response" | ||
} | ||
}, | ||
"operationId": "addPet", | ||
"security": [ | ||
{ | ||
"apiKey1": [], | ||
"apiKey3": [] | ||
} | ||
] | ||
} | ||
} | ||
}, | ||
"securityDefinitions": { | ||
"apiKey1": { | ||
"type": "apiKey", | ||
"name": "X-API-Key", | ||
"in": "header" | ||
}, | ||
"apiKey3": { | ||
"type": "apiKey", | ||
"name": "X-API-Key", | ||
"in": "query" | ||
} | ||
} | ||
} |
27 changes: 27 additions & 0 deletions
27
tests/openapi/checks/resource/generic/example_ClearTextAPIKey/fail3.yaml
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,27 @@ | ||
swagger: "2.0" | ||
info: | ||
title: Simple API overview | ||
version: 1.0.0 | ||
schemes: | ||
- https | ||
- http | ||
paths: | ||
/pets: | ||
post: | ||
description: Creates a new pet in the store | ||
responses: | ||
"200": | ||
description: 200 response | ||
operationId: addPet | ||
security: | ||
- apiKey1: [] | ||
apiKey3: [] | ||
securityDefinitions: | ||
apiKey1: | ||
type: apiKey | ||
name: X-API-Key | ||
in: header | ||
apiKey3: | ||
type: apiKey | ||
name: X-API-Key | ||
in: query |
56 changes: 56 additions & 0 deletions
56
tests/openapi/checks/resource/generic/example_ClearTextAPIKey/fail4.json
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,56 @@ | ||
{ | ||
"openapi": "3.0.0", | ||
"info": { | ||
"title": "Simple API overview", | ||
"version": "1.0.0" | ||
}, | ||
"servers": [ | ||
{ | ||
"url": "https://localhost:8000", | ||
"description": "Local server" | ||
}, | ||
{ | ||
"url": "http://example.com", | ||
"description": "Example" | ||
} | ||
], | ||
"paths": { | ||
"/pets": { | ||
"post": { | ||
"description": "Creates a new pet in the store", | ||
"responses": { | ||
"200": { | ||
"description": "200 response" | ||
} | ||
}, | ||
"operationId": "addPet", | ||
"security": [ | ||
{ | ||
"apiKey1": [], | ||
"apiKey2": [], | ||
"apiKey3": [] | ||
} | ||
] | ||
} | ||
} | ||
}, | ||
"components": { | ||
"securitySchemes": { | ||
"apiKey1": { | ||
"type": "apiKey", | ||
"name": "X-API-Key", | ||
"in": "header" | ||
}, | ||
"apiKey2": { | ||
"type": "apiKey", | ||
"name": "X-API-Key", | ||
"in": "cookie" | ||
}, | ||
"apiKey3": { | ||
"type": "apiKey", | ||
"name": "X-API-Key", | ||
"in": "query" | ||
} | ||
} | ||
} | ||
} |
35 changes: 35 additions & 0 deletions
35
tests/openapi/checks/resource/generic/example_ClearTextAPIKey/fail4.yaml
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,35 @@ | ||
openapi: 3.0.0 | ||
info: | ||
title: Simple API overview | ||
version: 1.0.0 | ||
servers: | ||
- url: https://localhost:8000 | ||
description: Local server | ||
- url: http://example.com | ||
description: example | ||
paths: | ||
/pets: | ||
post: | ||
description: Creates a new pet in the store | ||
responses: | ||
'200': | ||
description: 200 response | ||
operationId: addPet | ||
security: | ||
- apiKey1: [] | ||
apiKey2: [] | ||
apiKey3: [] | ||
components: | ||
securitySchemes: | ||
apiKey1: | ||
type: apiKey | ||
name: X-API-Key | ||
in: header | ||
apiKey2: | ||
type: apiKey | ||
name: X-API-Key | ||
in: cookie | ||
apiKey3: | ||
type: apiKey | ||
name: X-API-Key | ||
in: query |
41 changes: 41 additions & 0 deletions
41
tests/openapi/checks/resource/generic/example_ClearTextAPIKey/pass3.json
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,41 @@ | ||
{ | ||
"swagger": "2.0", | ||
"info": { | ||
"title": "Simple API overview", | ||
"version": "1.0.0" | ||
}, | ||
"schemes": [ | ||
"https" | ||
], | ||
"paths": { | ||
"/pets": { | ||
"post": { | ||
"description": "Creates a new pet in the store", | ||
"responses": { | ||
"200": { | ||
"description": "200 response" | ||
} | ||
}, | ||
"operationId": "addPet", | ||
"security": [ | ||
{ | ||
"apiKey1": [], | ||
"apiKey3": [] | ||
} | ||
] | ||
} | ||
} | ||
}, | ||
"securityDefinitions": { | ||
"apiKey1": { | ||
"type": "apiKey", | ||
"name": "X-API-Key", | ||
"in": "header" | ||
}, | ||
"apiKey3": { | ||
"type": "apiKey", | ||
"name": "X-API-Key", | ||
"in": "query" | ||
} | ||
} | ||
} |
26 changes: 26 additions & 0 deletions
26
tests/openapi/checks/resource/generic/example_ClearTextAPIKey/pass3.yaml
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,26 @@ | ||
swagger: "2.0" | ||
info: | ||
title: Simple API overview | ||
version: 1.0.0 | ||
schemes: | ||
- https | ||
paths: | ||
/pets: | ||
post: | ||
description: Creates a new pet in the store | ||
responses: | ||
"200": | ||
description: 200 response | ||
operationId: addPet | ||
security: | ||
- apiKey1: [] | ||
apiKey3: [] | ||
securityDefinitions: | ||
apiKey1: | ||
type: apiKey | ||
name: X-API-Key | ||
in: header | ||
apiKey3: | ||
type: apiKey | ||
name: X-API-Key | ||
in: query |
52 changes: 52 additions & 0 deletions
52
tests/openapi/checks/resource/generic/example_ClearTextAPIKey/pass4.json
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,52 @@ | ||
{ | ||
"openapi": "3.0.0", | ||
"info": { | ||
"title": "Simple API overview", | ||
"version": "1.0.0" | ||
}, | ||
"servers": [ | ||
{ | ||
"url": "https://localhost:8000", | ||
"description": "Local server" | ||
} | ||
], | ||
"paths": { | ||
"/pets": { | ||
"post": { | ||
"description": "Creates a new pet in the store", | ||
"responses": { | ||
"200": { | ||
"description": "200 response" | ||
} | ||
}, | ||
"operationId": "addPet", | ||
"security": [ | ||
{ | ||
"apiKey1": [], | ||
"apiKey2": [], | ||
"apiKey3": [] | ||
} | ||
] | ||
} | ||
} | ||
}, | ||
"components": { | ||
"securitySchemes": { | ||
"apiKey1": { | ||
"type": "apiKey", | ||
"name": "X-API-Key", | ||
"in": "header" | ||
}, | ||
"apiKey2": { | ||
"type": "apiKey", | ||
"name": "X-API-Key", | ||
"in": "cookie" | ||
}, | ||
"apiKey3": { | ||
"type": "apiKey", | ||
"name": "X-API-Key", | ||
"in": "query" | ||
} | ||
} | ||
} | ||
} |
33 changes: 33 additions & 0 deletions
33
tests/openapi/checks/resource/generic/example_ClearTextAPIKey/pass4.yaml
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,33 @@ | ||
openapi: 3.0.0 | ||
info: | ||
title: Simple API overview | ||
version: 1.0.0 | ||
servers: | ||
- url: https://localhost:8000 | ||
description: Local server | ||
paths: | ||
/pets: | ||
post: | ||
description: Creates a new pet in the store | ||
responses: | ||
'200': | ||
description: 200 response | ||
operationId: addPet | ||
security: | ||
- apiKey1: [] | ||
apiKey2: [] | ||
apiKey3: [] | ||
components: | ||
securitySchemes: | ||
apiKey1: | ||
type: apiKey | ||
name: X-API-Key | ||
in: header | ||
apiKey2: | ||
type: apiKey | ||
name: X-API-Key | ||
in: cookie | ||
apiKey3: | ||
type: apiKey | ||
name: X-API-Key | ||
in: query |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters