-
Notifications
You must be signed in to change notification settings - Fork 11
feat: Support to generate HTTP Response Security Event #260
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
sumitsuthar
wants to merge
15
commits into
main
Choose a base branch
from
response_event
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Changes from all commits
Commits
Show all changes
15 commits
Select commit
Hold shift + click to select a range
40c0d86
handling to generate response event
sumitsuthar 63ad5c9
updated response transaction event
sumitsuthar 2433bce
updated logic to enable response hook and processing of rxss on basis…
sumitsuthar a1b1f2c
minor fix
sumitsuthar e4fe5ca
minor fix
sumitsuthar 7d3f31c
handling to generate reposne event only for vulnerable
sumitsuthar 1493fbf
handling to truncate http response
sumitsuthar c45c366
Merge branch 'main' into response_event
sumitsuthar 5eed03b
resolve merge conficts
sumitsuthar 07ac9e3
minor fix
sumitsuthar 0e8df87
minor fix
sumitsuthar a82873e
removed hardcoded report_http_response flag
sumitsuthar ad05b1a
handling to send http response event over ws
sumitsuthar f8aa4c1
handling to not compute body for rxss in case of report_http_response…
sumitsuthar 3a5fc83
merged main branch
sumitsuthar File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Check failure
Code scanning / CodeQL
Clear-text logging of sensitive information
Copilot Autofix
AI over 1 year ago
To fix the problem, we need to ensure that sensitive information is not logged in clear text. The best way to fix this without changing existing functionality is to sanitize the
transactionEventobject before logging it. We can remove or mask sensitive fields from the object before converting it to a JSON string and logging it.We will modify the
generateTransactionEventfunction in thelib/instrumentation-security/hooks/http/nr-http.jsfile to sanitize thetransactionEventobject before logging it. Specifically, we will remove or mask the sensitive fields such asapplicationUUID,policyVersion,collectorVersion, andhttpRequest.