|
1 | | -const { startSubsequentSecureCodeBoxScan } = require("./scan-helpers"); |
2 | | -const isMatch = require("lodash.ismatch"); |
3 | | - |
4 | | -async function handle({ scan, getFindings }) { |
5 | | - const findings = await getFindings(); |
6 | | - const cascadingRules = await getCascadingRules(); |
7 | | - |
8 | | - const cascadingScans = getCascadingScans(findings, cascadingRules); |
9 | | - |
10 | | - for (const { scanType, parameters } of cascadingScans) { |
11 | | - await startSubsequentSecureCodeBoxScan({ |
12 | | - parentScan: scan, |
13 | | - scanType, |
14 | | - parameters, |
| 1 | +"use strict"; |
| 2 | +var __awaiter = (this && this.__awaiter) || function (thisArg, _arguments, P, generator) { |
| 3 | + function adopt(value) { return value instanceof P ? value : new P(function (resolve) { resolve(value); }); } |
| 4 | + return new (P || (P = Promise))(function (resolve, reject) { |
| 5 | + function fulfilled(value) { try { step(generator.next(value)); } catch (e) { reject(e); } } |
| 6 | + function rejected(value) { try { step(generator["throw"](value)); } catch (e) { reject(e); } } |
| 7 | + function step(result) { result.done ? resolve(result.value) : adopt(result.value).then(fulfilled, rejected); } |
| 8 | + step((generator = generator.apply(thisArg, _arguments || [])).next()); |
| 9 | + }); |
| 10 | +}; |
| 11 | +var __generator = (this && this.__generator) || function (thisArg, body) { |
| 12 | + var _ = { label: 0, sent: function() { if (t[0] & 1) throw t[1]; return t[1]; }, trys: [], ops: [] }, f, y, t, g; |
| 13 | + return g = { next: verb(0), "throw": verb(1), "return": verb(2) }, typeof Symbol === "function" && (g[Symbol.iterator] = function() { return this; }), g; |
| 14 | + function verb(n) { return function (v) { return step([n, v]); }; } |
| 15 | + function step(op) { |
| 16 | + if (f) throw new TypeError("Generator is already executing."); |
| 17 | + while (_) try { |
| 18 | + if (f = 1, y && (t = op[0] & 2 ? y["return"] : op[0] ? y["throw"] || ((t = y["return"]) && t.call(y), 0) : y.next) && !(t = t.call(y, op[1])).done) return t; |
| 19 | + if (y = 0, t) op = [op[0] & 2, t.value]; |
| 20 | + switch (op[0]) { |
| 21 | + case 0: case 1: t = op; break; |
| 22 | + case 4: _.label++; return { value: op[1], done: false }; |
| 23 | + case 5: _.label++; y = op[1]; op = [0]; continue; |
| 24 | + case 7: op = _.ops.pop(); _.trys.pop(); continue; |
| 25 | + default: |
| 26 | + if (!(t = _.trys, t = t.length > 0 && t[t.length - 1]) && (op[0] === 6 || op[0] === 2)) { _ = 0; continue; } |
| 27 | + if (op[0] === 3 && (!t || (op[1] > t[0] && op[1] < t[3]))) { _.label = op[1]; break; } |
| 28 | + if (op[0] === 6 && _.label < t[1]) { _.label = t[1]; t = op; break; } |
| 29 | + if (t && _.label < t[2]) { _.label = t[2]; _.ops.push(op); break; } |
| 30 | + if (t[2]) _.ops.pop(); |
| 31 | + _.trys.pop(); continue; |
| 32 | + } |
| 33 | + op = body.call(thisArg, _); |
| 34 | + } catch (e) { op = [6, e]; y = 0; } finally { f = t = 0; } |
| 35 | + if (op[0] & 5) throw op[1]; return { value: op[0] ? op[1] : void 0, done: true }; |
| 36 | + } |
| 37 | +}; |
| 38 | +exports.__esModule = true; |
| 39 | +exports.getCascadingScans = exports.handle = void 0; |
| 40 | +var lodash_1 = require("lodash"); |
| 41 | +var Mustache = require("mustache"); |
| 42 | +var scan_helpers_1 = require("./scan-helpers"); |
| 43 | +function handle(_a) { |
| 44 | + var scan = _a.scan, getFindings = _a.getFindings; |
| 45 | + return __awaiter(this, void 0, void 0, function () { |
| 46 | + var findings, cascadingRules, cascadingScans, _i, cascadingScans_1, _b, name_1, parameters; |
| 47 | + return __generator(this, function (_c) { |
| 48 | + switch (_c.label) { |
| 49 | + case 0: return [4 /*yield*/, getFindings()]; |
| 50 | + case 1: |
| 51 | + findings = _c.sent(); |
| 52 | + return [4 /*yield*/, getCascadingRules()]; |
| 53 | + case 2: |
| 54 | + cascadingRules = _c.sent(); |
| 55 | + cascadingScans = getCascadingScans(findings, cascadingRules); |
| 56 | + _i = 0, cascadingScans_1 = cascadingScans; |
| 57 | + _c.label = 3; |
| 58 | + case 3: |
| 59 | + if (!(_i < cascadingScans_1.length)) return [3 /*break*/, 6]; |
| 60 | + _b = cascadingScans_1[_i], name_1 = _b.name, parameters = _b.parameters; |
| 61 | + return [4 /*yield*/, scan_helpers_1.startSubsequentSecureCodeBoxScan({ |
| 62 | + parentScan: scan, |
| 63 | + scanType: name_1, |
| 64 | + parameters: parameters |
| 65 | + })]; |
| 66 | + case 4: |
| 67 | + _c.sent(); |
| 68 | + _c.label = 5; |
| 69 | + case 5: |
| 70 | + _i++; |
| 71 | + return [3 /*break*/, 3]; |
| 72 | + case 6: return [2 /*return*/]; |
| 73 | + } |
| 74 | + }); |
15 | 75 | }); |
16 | | - } |
17 | 76 | } |
18 | | - |
19 | | -async function getCascadingRules() { |
20 | | - // Todo: Get all CascadingRules of the current Namespace via k8s api |
21 | | - return []; |
| 77 | +exports.handle = handle; |
| 78 | +function getCascadingRules() { |
| 79 | + return __awaiter(this, void 0, void 0, function () { |
| 80 | + return __generator(this, function (_a) { |
| 81 | + switch (_a.label) { |
| 82 | + case 0: return [4 /*yield*/, scan_helpers_1.getCascadingRulesFromCluster()]; |
| 83 | + case 1: |
| 84 | + // Explicit Cast to the proper Type |
| 85 | + return [2 /*return*/, _a.sent()]; |
| 86 | + } |
| 87 | + }); |
| 88 | + }); |
22 | 89 | } |
23 | | - |
24 | | -// Todo remove eslint disable |
25 | | -// eslint-disable-next-line no-unused-vars |
| 90 | +/** |
| 91 | + * Goes thought the Findings and the CascadingRules |
| 92 | + * and returns a List of Scans which should be started based on both. |
| 93 | + */ |
26 | 94 | function getCascadingScans(findings, cascadingRules) { |
27 | | - const cascadingScans = []; |
28 | | - |
29 | | - for (const cascadingRule of cascadingRules) { |
30 | | - for (const finding of findings) { |
31 | | - const matches = cascadingRule.spec.matches.some((matchesRule) => |
32 | | - isMatch(finding, matchesRule) |
33 | | - ); |
34 | | - |
35 | | - if (matches) { |
36 | | - // Todo templating |
37 | | - cascadingScans.push(cascadingRule.spec.scanSpec); |
38 | | - } |
| 95 | + var cascadingScans = []; |
| 96 | + for (var _i = 0, cascadingRules_1 = cascadingRules; _i < cascadingRules_1.length; _i++) { |
| 97 | + var cascadingRule = cascadingRules_1[_i]; |
| 98 | + var _loop_1 = function (finding) { |
| 99 | + var matches = cascadingRule.spec.matches.some(function (matchesRule) { |
| 100 | + return lodash_1.isMatch(finding, matchesRule); |
| 101 | + }); |
| 102 | + if (matches) { |
| 103 | + var _a = cascadingRule.spec.scanSpec, name_2 = _a.name, parameters = _a.parameters; |
| 104 | + cascadingScans.push({ |
| 105 | + name: Mustache.render(name_2, finding), |
| 106 | + parameters: parameters.map(function (parameter) { |
| 107 | + return Mustache.render(parameter, finding); |
| 108 | + }) |
| 109 | + }); |
| 110 | + } |
| 111 | + }; |
| 112 | + for (var _a = 0, findings_1 = findings; _a < findings_1.length; _a++) { |
| 113 | + var finding = findings_1[_a]; |
| 114 | + _loop_1(finding); |
| 115 | + } |
39 | 116 | } |
40 | | - } |
41 | | - |
42 | | - return cascadingScans; |
| 117 | + return cascadingScans; |
43 | 118 | } |
44 | | - |
45 | | -module.exports.getCascadingScans = getCascadingScans; |
46 | | -module.exports.handle = handle; |
| 119 | +exports.getCascadingScans = getCascadingScans; |
0 commit comments