Skip to content

Commit 268eaf9

Browse files
skullcmdclaude
andcommitted
fix(plugins): SwaggerUIPlugin requires 2xx + body validation, not just path
The SwaggerUIPlugin matcher fired on any document whose path contained "swagger", "openapi", or "api-docs" — with no HTTP status check, no content-type check, and no positive-evidence body validation. An audit of scans #21 and #25 found 211/211 + 39/39 false positives; every spot-checked target was a CDN edge returning 4xx error pages or unrelated content with zero swagger keywords. matched_signals was always empty and evidence carried no proof of why the plugin fired. Tighten the matcher with per-path validators: * HTTP status must be 2xx (4xx/5xx never match). * JSON spec paths (/openapi.json, /swagger.json, /v2/api-docs, /v3/api-docs, /api-docs.json): body must trim-start with `{` and contain a top-level `"openapi"` or `"swagger"` key in the first 4 KB. * YAML spec paths (/openapi.yml, /openapi.yaml, /swagger.yml, /swagger.yaml): body must start with `openapi:` or `swagger:` after whitespace. * Swagger-UI HTML paths (/swagger-ui*, /swagger, /api-docs): body must reference swagger-ui-bundle.js, swagger-ui-standalone-preset, swagger-ui-dist, or swagger-ui.css within the first 16 KB. * Bodies under 50 bytes never match. Findings now populate `matched_signals` with the actual matched substring and `evidence` with a status/type-tagged snippet built via `build_evidence`, so future audits can see why the plugin fired. The new helper `push_plugin_finding_candidate_with_signals` carries matched_signals through; the existing `push_plugin_finding_candidate` delegates to it with an empty vec, so the other 78 callers are unchanged. Tests: 8 new cases cover non-2xx rejection, weak-evidence rejection (HTML without swagger-ui markers, JSON without openapi/swagger keys, sub-50-byte bodies, YAML without spec prefix) and positive cases for OpenAPI 3.x JSON, Swagger 2.0 JSON, and swagger-ui HTML pages. cargo build --workspace clean. cargo test --workspace --lib --bins --no-fail-fast: 410 passed / 0 failed / 3 ignored (was ~397 baseline, +8 new SwaggerUI tests). Effect kicks in on next bundled-rules redeploy + worker update. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
1 parent 8d180f8 commit 268eaf9

1 file changed

Lines changed: 409 additions & 12 deletions

File tree

0 commit comments

Comments
 (0)