add IAST code injection tests for java - #7445
Conversation
|
|
|
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2dac0de616
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| package com.datadoghq.system_tests.iast.utils; | ||
|
|
||
| import bsh.EvalError; | ||
| import bsh.Interpreter; |
There was a problem hiding this comment.
Add BeanShell to the OTel Spring Boot build
When the java_otel Spring Boot image is built, utils/build/docker/java_otel/spring-boot-otel.Dockerfile copies the shared iast-common sources and that POM adds ../iast-common/src/main/java/ as compile sources, but utils/build/docker/java_otel/spring-boot/pom.xml does not declare the new BeanShell dependency. This new import therefore makes that supported weblog fail compilation with package bsh does not exist; add the same org.apache-extras.beanshell:bsh dependency there or keep this helper out of sources used by the OTel weblog.
Useful? React with 👍 / 👎.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Motivation
The IAST
CODE_INJECTIONsink was not covered by system-tests for the Java tracer. This adds the weblog endpoints and enables the existingtest_code_injection.pytests so the Java library's code-injection detection (BeanShell sink) is validated end-to-end.Changes
CodeInjectionExampleshelper iniast-commonthat triggers the sink by evaluating input through BeanShell (bsh.Interpreter.eval), with an insecure (tainted input) and secure (hardcoded literal) variant.POST /iast/code_injection/test_insecureandPOST /iast/code_injection/test_securein the weblogs that carry the full IAST sink surface:akka-http,jersey-grizzly2,resteasy-netty3,spring-boot,vertx3,vertx4.bshdependency toiast-common(optional) and to each weblog that implements the endpoint.TestCodeInjectionandTestCodeInjection_StackTraceinmanifests/java.ymlfromv1.65.0-SNAPSHOT:play/ratpack:incomplete_test_app (endpoint not implemented)— these weblogs do not implement the IAST sink endpoints.spring-boot-3-native:irrelevant (GraalVM. Tracing support only).Workflow
🚀 Once your PR is reviewed and the CI green, you can merge it!
🛟 #apm-shared-testing 🛟
Reviewer checklist
tests/ormanifests/is modified ? I have the approval from R&P teambuild-XXX-imagelabel is present