
Globaler API-Integritätsprüfer
Installieren Sie opam, um die Test-API zu erstellen.
Installieren Sie git, python3, pip und .NET, um RESTler und Schemathesis zu erstellen.
Installieren Sie cargo, um Gaia zu erstellen.
Installieren Sie docker v26.0.1 und docker compose v2.26.1, um Gaia mit dem ELK-Stack zu erstellen (optional, falls nicht).
Installieren Sie node >= v18.0.0 und npm >= v8.6.0
Um einen lokalen opam-Switch zu erstellen:
make opam-switch
make deps
make build
make build-test
make generate-swagger
make clean-swagger
make format
make clean-build-files
make clean
./_bin/gaia --help
gaia --configuration <configuration> --openapi-path <openapi-path> --workdir-path <workdir-path> --verbose <verbose>
workdir-path: Das Arbeitsverzeichnis, in dem Sie die verschiedenen Protokolle der Fuzzer finden.
openapi-path: Pfad der OpenAPI-Datei der realen API. Erforderlich, wenn Sie Fuzzing oder Monitoring verwenden, aber nicht für Statistiken
verbose : Der Grad der Ausführlichkeit {NOTHING, LOW, MID, HIGH, ALL} (Standardwert: NOTHING)
configuration: Der Pfad der JSON-Datei, die Folgendes enthält:
{
"configuration": {
// One of : fuzzing or monitoring
"fuzzing": {
//Required
"config_fuzzer": {
//Required
// In hours
"timeout": 1,
//Optional
// Disable fuzzers
"disable_fuzzers": [{
"Restler":{
// Bfs, BfsFast, BfsCheap or RandomWalk
"strategy" : "Bfs"
}
},
"Schemathesis",
{"Custom": {"id": "1"}}
],
//Optional
"custom_fuzzers": [
"<command line that can accept `--output_dir <PATH>`, `--openapi_path <PATH>` and `--timeout <FLOAT>` as arguments>"
],
//Optional
"generation_config": {
//optional (Required if you set a function to generate a value)
"lib_path": "Absolute path to the dynamic library (.so, .dll, or .rs).",
//Optional
"generate_string": {
//One of : Command, Value, File path or Function
"command": "<command line that returns a string array>",
//Or
"value": ["fuzzstring"],
//Or
"function": "<function() that returns a string array>",
//Or
"file": "The file path to the dictionary of values"
},
//Optional
"generate_datetime": {
//One of : Command, Value, File path or Function
"command": "<command line that returns a datetime array in a string format>",
//Or
"value": ["2019-06-26T20:20:39+00:00"],
//Or
"function": "<function() that returns a datetime array in a string format>",
//Or
"file": "The file path to the dictionary of values"
},
//Optional
"generate_date": {
//One of : Command, Value, File path or Function
"command": "<command line that returns a date array in a string format>",
//Or
"value": ["2019-06-26"],
//Or
"function": "<function() that returns a date array in a string format>",
//Or
"file": "The file path to the dictionary of values"
},
//Optional
"generate_int": {
//One of : Command, Value, File path or Function
"command": "<command line that returns an int array in a string format>",
//Or
"value": ["0"],
//Or
"function": "<function() that returns an int array in a string format>",
//Or
"file": "The file path to the dictionary of values"
},
//Optional
"generate_number": {
//One of : Command, Value, File path or Function
"command": "<command line that returns a float array in a string format>",
//Or
"value": ["1.5"],
//Or
"function": "<function() that returns a float array in a string format>",
//Or
"file": "The file path to the dictionary of values"
},
//Optional
"generate_object": {
//One of : Command, Value, File path or Function
"command": "<command line that returns a json object array in a string format>",
//Or
"value": ["{\"k\" : {\"v\" : \"value\" }}"],
//Or
"function": "<function() that returns a json object array in a string format>",
//Or
"file": "The file path to the dictionary of values"
},
//Optional
"generate_path_parameter": {
//One of : Command, Value, File path or Function
"command": "<command line that returns a key-value map with a string key referring to a path parameter and a string array of values>",
//Or
"value": {
"k": {
"v": ["value"]
}
},
//Or
"function": "<function() that returns a key-value map with a string key referring to a path parameter and a string array of values>",
//Or
"file": "The file path to the dictionary of values"
},
//Optional
"generate_query_parameter": {
//One of : Command, Value, File path or Function
"command": "<command line that returns a key-value map with a string key referring to a query parameter and a string array of values>",
//Or
"value": {
"k": {
"v": ["value"]
}
},
//Or
"function": "<function() that returns a key-value map with a string key referring to a query parameter and a string array of values>",
//Or
"file": "The file path to the dictionary of values"
}
}
},
//Required
"config_process_manager": {
//Optional
"config_reset": {
//Required
"reset_lib": "Absolute path to the dynamic library (.so, .dll, or .rs).",
//Required
"function": "Function name that takes two strings as arguments and returns a unit. The first string represents the log in JSON format, and the second represents the path to the real-time log file."
},
//Required
"config_proxy": {
//Optional
"headers_config": {
//Optional
"custom_headers": [
{
//Required
"title": "title",
//Required
"header_type": {
//One of : Command or Value
"Command": {
//Required
"cmd": "<Command that returns the value of the header>",
//Required
//Refresh value in milliseconds
"duration": 0
},
// or
"Value": { "value": "Header value" }
}
}
]
},
//Optional
"openapi_config": {
//Optional
"responses_to_string": true, // Change the type of the responses to string
//Optional
"requests_config": {
//One of : Exclude or Only
"only": {
//Required
"requests": [
{
//Required
"path": "Regex that represents a path",
//Required
"methods": [
"Get",
"Put",
"Post",
"Delete",
"Options",
"Head",
"Patch",
"Trace"
]
}
]
},
//Or
"Exclude": {
//Required
"requests": [
{
//Required
"path": "Regex that represents a path",
//Optional: Defaults to all methods if not specified.
"methods": [
"Get",
"Put",
"Post",
"Delete",
"Options",
"Head",
"Patch",
"Trace"
]
}
]
}
}
},
//Optional
"stream_response_services": [
{
//Required
"path": "Regex that represents a path",
//Optional: Defaults to all methods if not specified.
"methods": [
"Get",
"Put",
"Post",
"Delete",
"Options",
"Head",
"Patch",
"Trace"
]
}
]
},
//Optional
"use_sync_requests" : true
}
},
"monitoring": {
"config_monitoring": {
//One of : log_file_path or service
"log_file_path": {
//Required
"path": "/home/log.log"
},
"service": {
//Required
"url": "http://localhost:3000/log"
}
}
}
},
//Optional
"config_checker": {
//Optional
"checkers_cmd": [
"<command line that take a string as an argument and return unit. This string represents the log in JSON format>"
],
//Optional
"checkers_lib": [
{
//Required
"checkers_lib": "Absolute path to the dynamic library (.so, .dll, or .rs).",
//Required
"function_names": [
"Function names that take a string as an argument and return unit. This string represents the log in JSON format"
]
}
]
},
//Optional
"config_checker_elk_stack": {
//Required
"kibana_port": 5602 //Kibana url : http://localhost:{kibana_port}
},
//Optional
"config_statistics": {
//Required
"process": {
//One of : docker, process or service
"docker": {
//Required
"container_id": "89u32eew2r"
},
"process": {
//Required
"pid": 1100293
},
"service": {
//Required
"url": "http://localhost:3000/statistics"
}
}
},
//Optional
"scanner": true
}
{
"id" : 9009,
"request": {
"method": "GET",
"url": "http://localhost:8080/api/data",
"headers": [
["connection", "keep-alive"],
["accept", "*/*"],
["user-agent", "schemathesis/3.24.3"],
["host", "localhost:8081"],
["accept-encoding", "gzip, deflate"],
["authorization", "Bearer"],
["x-schemathesis-testcaseid", "97pK1I"],
["authorization", "Bearer Test"]
],
"params": [],
"body": "",
"timestamp": "2024-06-17T12:43:21.717+00:00"
},
"response": {
"status_code": 403,
"headers": [
["access-control-allow-headers", "accept, content-type"],
["access-control-allow-origin", "*"],
["content-type", "application/json"],
["content-length", "70"]
],
"body": "{\"error\":\"get_data\",\"exception\":\"sender Test should be connected\"}",
"timestamp": "2024-06-17T12:43:21.717+00:00"
},
"reset": false
}
{
"request": {
"method": "POST",
"url": "http://localhost:20000/injection/block",
"headers": [
["user-agent", "restler/9.2.3"],
["content-type", "application/json"],
["accept", "application/json"],
["x-restler-sequence-id", "20f34e2b-13e8-4861-a7aa-77df3dff5ad6"],
["host", "localhost:22333"],
["content-length", "225"]
],
"params": [
["async", "fuzzstring"],
["force", "fuzzstring"],
["chain", "fuzzstring"]
],
"body": {
"data": "fuzzstring",
"operations": [[{ "branch": { "fuzz": false }, "data": "fuzzstring" }]]
},
"timestamp": "2024-06-17T12:43:21.717+00:00"
},
"response": {
"status_code": 400,
"headers": [
["content-type", "text/plain"],
["transfer-encoding", "chunked"]
],
"body": null,
"timestamp": "2024-06-17T12:43:21.722+00:00"
},
"reset": false
}
Urheberrecht © 2024, Functori [email protected].