Commit 268eaf9
fix(plugins): SwaggerUIPlugin requires 2xx + body validation, not just path
The SwaggerUIPlugin matcher fired on any document whose path contained
"swagger", "openapi", or "api-docs" — with no HTTP status check, no
content-type check, and no positive-evidence body validation. An audit
of scans #21 and #25 found 211/211 + 39/39 false positives; every
spot-checked target was a CDN edge returning 4xx error pages or
unrelated content with zero swagger keywords. matched_signals was
always empty and evidence carried no proof of why the plugin fired.
Tighten the matcher with per-path validators:
* HTTP status must be 2xx (4xx/5xx never match).
* JSON spec paths (/openapi.json, /swagger.json, /v2/api-docs, /v3/api-docs,
/api-docs.json): body must trim-start with `{` and contain a top-level
`"openapi"` or `"swagger"` key in the first 4 KB.
* YAML spec paths (/openapi.yml, /openapi.yaml, /swagger.yml,
/swagger.yaml): body must start with `openapi:` or `swagger:` after
whitespace.
* Swagger-UI HTML paths (/swagger-ui*, /swagger, /api-docs): body must
reference swagger-ui-bundle.js, swagger-ui-standalone-preset,
swagger-ui-dist, or swagger-ui.css within the first 16 KB.
* Bodies under 50 bytes never match.
Findings now populate `matched_signals` with the actual matched
substring and `evidence` with a status/type-tagged snippet built via
`build_evidence`, so future audits can see why the plugin fired.
The new helper `push_plugin_finding_candidate_with_signals` carries
matched_signals through; the existing `push_plugin_finding_candidate`
delegates to it with an empty vec, so the other 78 callers are
unchanged.
Tests: 8 new cases cover non-2xx rejection, weak-evidence rejection
(HTML without swagger-ui markers, JSON without openapi/swagger keys,
sub-50-byte bodies, YAML without spec prefix) and positive cases for
OpenAPI 3.x JSON, Swagger 2.0 JSON, and swagger-ui HTML pages.
cargo build --workspace clean. cargo test --workspace --lib --bins
--no-fail-fast: 410 passed / 0 failed / 3 ignored (was ~397 baseline,
+8 new SwaggerUI tests).
Effect kicks in on next bundled-rules redeploy + worker update.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>1 parent 8d180f8 commit 268eaf9
1 file changed
Lines changed: 409 additions & 12 deletions
0 commit comments