-
Notifications
You must be signed in to change notification settings - Fork 408
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix(asm): fixing exploit prevention on custom redirect action [backport 2.11] #10654
Conversation
Check for redirecting actions as well for blocking requests with exploit prevention. Also add regression tests in threat tests. ## Checklist - [x] PR author has checked that all the criteria below are met - The PR description includes an overview of the change - The PR description articulates the motivation for the change - The change includes tests OR the PR description describes a testing strategy - The PR description notes risks associated with the change, if any - Newly-added code is easy to change - The change follows the [library release note guidelines](https://ddtrace.readthedocs.io/en/stable/releasenotes.html) - The change includes or references documentation updates if necessary - Backport labels are set (if [applicable](https://ddtrace.readthedocs.io/en/latest/contributing.html#backporting)) ## Reviewer Checklist - [ ] Reviewer has checked that all the criteria below are met - Title is accurate - All changes are related to the pull request's stated goal - Avoids breaking [API](https://ddtrace.readthedocs.io/en/stable/versioning.html#interfaces) changes - Testing strategy adequately addresses listed risks - Newly-added code is easy to change - Release note makes sense to a user of the library - If necessary, author has acknowledged and discussed the performance implications of this PR as reported in the benchmarks PR comment - Backport labels are set in a manner that is consistent with the [release branch maintenance policy](https://ddtrace.readthedocs.io/en/latest/contributing.html#backporting) (cherry picked from commit 69c090b)
Datadog ReportBranch report: ✅ 0 Failed, 113016 Passed, 875 Skipped, 37m 0.62s Total duration (5m 45.09s time saved) |
Codecov ReportAll modified and coverable lines are covered by tests ✅
Additional details and impacted files@@ Coverage Diff @@
## 2.11 #10654 +/- ##
===========================================
- Coverage 34.18% 10.56% -23.62%
===========================================
Files 1385 1386 +1
Lines 129280 129552 +272
===========================================
- Hits 44191 13691 -30500
- Misses 85089 115861 +30772 ☔ View full report in Codecov by Sentry. |
Backport 69c090b from #10644 to 2.11.
Check for redirecting actions as well for blocking requests with exploit prevention.
Also add regression tests in threat tests.
Checklist
Reviewer Checklist