|
6 | 6 | import com.datadog.iast.model.Source;
|
7 | 7 | import com.datadog.iast.model.SourceType;
|
8 | 8 | import com.datadog.iast.taint.Ranges;
|
| 9 | +import com.datadog.iast.taint.TaintedObject; |
9 | 10 | import com.datadog.iast.taint.TaintedObjects;
|
10 | 11 | import datadog.trace.api.iast.source.WebModule;
|
11 | 12 | import java.io.BufferedReader;
|
12 | 13 | import java.io.InputStream;
|
| 14 | +import java.util.Collection; |
| 15 | +import java.util.List; |
| 16 | +import java.util.Map; |
| 17 | +import java.util.Set; |
13 | 18 | import javax.annotation.Nonnull;
|
14 | 19 | import javax.annotation.Nullable;
|
15 | 20 |
|
@@ -131,4 +136,100 @@ public void onHeaderValue(@Nullable final String headerName, @Nullable final Str
|
131 | 136 | taintedObjects.taintInputString(
|
132 | 137 | headerValue, new Source(SourceType.REQUEST_HEADER_VALUE, headerName, headerValue));
|
133 | 138 | }
|
| 139 | + |
| 140 | + @Override |
| 141 | + public void onCookieValue(@Nullable final String cookieName, @Nullable final String cookieValue) { |
| 142 | + if (!canBeTainted(cookieName)) { |
| 143 | + return; |
| 144 | + } |
| 145 | + final IastRequestContext ctx = IastRequestContext.get(); |
| 146 | + if (ctx == null) { |
| 147 | + return; |
| 148 | + } |
| 149 | + final TaintedObjects taintedObjects = ctx.getTaintedObjects(); |
| 150 | + taintedObjects.taintInputString( |
| 151 | + cookieValue, new Source(SourceType.REQUEST_COOKIE_VALUE, cookieName, cookieValue)); |
| 152 | + } |
| 153 | + |
| 154 | + @Override |
| 155 | + public void onJaxGetQueryParameters(@Nonnull Object multiValuedMap) { |
| 156 | + final IastRequestContext ctx = IastRequestContext.get(); |
| 157 | + if (ctx == null) { |
| 158 | + return; |
| 159 | + } |
| 160 | + final TaintedObjects taintedObjects = ctx.getTaintedObjects(); |
| 161 | + taintedObjects.taint(multiValuedMap, Ranges.EMPTY); |
| 162 | + } |
| 163 | + |
| 164 | + @Override |
| 165 | + public void onMultiValuedMapAccess( |
| 166 | + @Nonnull Object multiValuedMap, @Nonnull Object key, @Nonnull Object returnedValue) { |
| 167 | + final IastRequestContext ctx = IastRequestContext.get(); |
| 168 | + if (ctx == null) { |
| 169 | + return; |
| 170 | + } |
| 171 | + final TaintedObjects taintedObjects = ctx.getTaintedObjects(); |
| 172 | + TaintedObject taintedMultiValuedMap = taintedObjects.get(multiValuedMap); |
| 173 | + if (null != taintedMultiValuedMap && key instanceof String) { |
| 174 | + if (returnedValue instanceof String) { |
| 175 | + taintedObjects.taintInputString( |
| 176 | + (String) returnedValue, |
| 177 | + new Source(SourceType.REQUEST_PARAMETER_VALUE, (String) key, (String) returnedValue)); |
| 178 | + } else if (returnedValue instanceof List) { |
| 179 | + for (Object o : ((List) returnedValue)) { |
| 180 | + if (o instanceof String) { |
| 181 | + taintedObjects.taintInputString( |
| 182 | + (String) o, |
| 183 | + new Source(SourceType.REQUEST_PARAMETER_VALUE, (String) key, (String) o)); |
| 184 | + } |
| 185 | + } |
| 186 | + } |
| 187 | + } |
| 188 | + } |
| 189 | + |
| 190 | + @Override |
| 191 | + public void taintSetIfInputIsTainted(@Nonnull Set toTaint, @Nullable Object input) { |
| 192 | + final IastRequestContext ctx = IastRequestContext.get(); |
| 193 | + if (ctx == null) { |
| 194 | + return; |
| 195 | + } |
| 196 | + final TaintedObjects taintedObjects = ctx.getTaintedObjects(); |
| 197 | + TaintedObject tainted = taintedObjects.get(input); |
| 198 | + if (tainted != null) { |
| 199 | + for (Object o : toTaint) { |
| 200 | + if (o instanceof String) { |
| 201 | + taintedObjects.taintInputString( |
| 202 | + (String) o, new Source(SourceType.REQUEST_PARAMETER_VALUE, null, (String) o)); |
| 203 | + } else if (o instanceof Map.Entry) { |
| 204 | + Map.Entry entry = (Map.Entry) o; |
| 205 | + if (entry.getKey() instanceof String && entry.getValue() instanceof String) { |
| 206 | + taintedObjects.taintInputString( |
| 207 | + (String) entry.getValue(), |
| 208 | + new Source( |
| 209 | + SourceType.REQUEST_PARAMETER_VALUE, |
| 210 | + (String) entry.getKey(), |
| 211 | + (String) entry.getValue())); |
| 212 | + } |
| 213 | + } |
| 214 | + } |
| 215 | + } |
| 216 | + } |
| 217 | + |
| 218 | + @Override |
| 219 | + public void taintCollectionIfInputIsTainted(@Nonnull Collection toTaint, @Nullable Object input) { |
| 220 | + final IastRequestContext ctx = IastRequestContext.get(); |
| 221 | + if (ctx == null) { |
| 222 | + return; |
| 223 | + } |
| 224 | + final TaintedObjects taintedObjects = ctx.getTaintedObjects(); |
| 225 | + TaintedObject tainted = taintedObjects.get(input); |
| 226 | + if (tainted != null) { |
| 227 | + for (Object o : toTaint) { |
| 228 | + if (o instanceof String) { |
| 229 | + taintedObjects.taintInputString( |
| 230 | + (String) o, new Source(SourceType.REQUEST_PARAMETER_VALUE, null, (String) o)); |
| 231 | + } |
| 232 | + } |
| 233 | + } |
| 234 | + } |
134 | 235 | }
|
0 commit comments