amjadafanah / FX-SAAS-9

This project is for testing the security and quality of APIs in FX SaaS
0 stars 0 forks source link

FX-SAAS-9 : ApiV1AccountsSearchGetOtherRbac #1237

Open amjadafanah opened 6 years ago

amjadafanah commented 6 years ago

Project : FX-SAAS-9

Job : Dev

Env : Dev

Region : FXLabs/US_WEST_1

Result : fail

Status Code : 200

Headers : {X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Tue, 02 Oct 2018 11:28:57 GMT]}

Endpoint : http://13.56.210.25/api/v1/accounts/search

Request :

Response :
{ "requestId" : "None", "requestTime" : "2018-10-02T11:28:57.465+0000", "errors" : false, "messages" : [ ], "data" : [ { "id" : "8a8080fe663385cc016633a181b22ca6", "createdBy" : "8a8080cf65e02c0f0165e031fa6b0000", "createdDate" : "2018-10-02T07:15:14.482+0000", "modifiedBy" : "8a8080cf65e02c0f0165e031fa6b0000", "modifiedDate" : "2018-10-02T07:15:14.482+0000", "version" : null, "inactive" : false, "name" : "Default_SelfHosted", "region" : null, "accessKey" : null, "secretKey" : null, "org" : { "id" : "8a8080fe663385cc016633a181ae2ca4", "createdBy" : "8a8080cf65e02c0f0165e031fa6b0000", "createdDate" : "2018-10-02T07:15:14.478+0000", "modifiedBy" : "8a8080cf65e02c0f0165e031fa6b0000", "modifiedDate" : "2018-10-02T07:15:14.478+0000", "version" : null, "inactive" : false, "name" : "orgtest45" }, "accountType" : "Self_Hosted", "prop1" : null, "prop2" : null, "prop3" : null, "allowedRegions" : [ ] }, { "id" : "8a8080fe663385cc016633a181b22ca7", "createdBy" : "8a8080cf65e02c0f0165e031fa6b0000", "createdDate" : "2018-10-02T07:15:14.482+0000", "modifiedBy" : "8a8080cf65e02c0f0165e031fa6b0000", "modifiedDate" : "2018-10-02T07:15:14.482+0000", "version" : null, "inactive" : false, "name" : "FX Issues", "region" : null, "accessKey" : null, "secretKey" : null, "org" : { "id" : "8a8080fe663385cc016633a181ae2ca4", "createdBy" : "8a8080cf65e02c0f0165e031fa6b0000", "createdDate" : "2018-10-02T07:15:14.478+0000", "modifiedBy" : "8a8080cf65e02c0f0165e031fa6b0000", "modifiedDate" : "2018-10-02T07:15:14.478+0000", "version" : null, "inactive" : false, "name" : "orgtest45" }, "accountType" : "FX_Issues", "prop1" : null, "prop2" : null, "prop3" : null, "allowedRegions" : [ ] } ], "totalPages" : 1, "totalElements" : 2 }

Logs :
Assertion [@StatusCode == 403] resolved-to [200 == 403] result [Failed] --- FX Bot ---

amjadafanah commented 6 years ago

Project : FX-SAAS-9

Job : Dev

Env : Dev

Region : FXLabs/US_WEST_1

Result : fail

Status Code : 200

Headers : {X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Wed, 03 Oct 2018 11:04:51 GMT]}

Endpoint : http://13.56.210.25/api/v1/accounts/search

Request :

Response :
{ "requestId" : "None", "requestTime" : "2018-10-03T11:04:51.374+0000", "errors" : false, "messages" : [ ], "data" : [ { "id" : "8a8080fe663385cc016633a181b22ca6", "createdBy" : "8a8080cf65e02c0f0165e031fa6b0000", "createdDate" : "2018-10-02T07:15:14.482+0000", "modifiedBy" : "8a8080cf65e02c0f0165e031fa6b0000", "modifiedDate" : "2018-10-02T07:15:14.482+0000", "version" : null, "inactive" : false, "name" : "Default_SelfHosted", "region" : null, "accessKey" : null, "secretKey" : null, "org" : { "id" : "8a8080fe663385cc016633a181ae2ca4", "createdBy" : "8a8080cf65e02c0f0165e031fa6b0000", "createdDate" : "2018-10-02T07:15:14.478+0000", "modifiedBy" : "8a8080cf65e02c0f0165e031fa6b0000", "modifiedDate" : "2018-10-02T07:15:14.478+0000", "version" : null, "inactive" : false, "name" : "orgtest45" }, "accountType" : "Self_Hosted", "prop1" : null, "prop2" : null, "prop3" : null, "allowedRegions" : [ ] }, { "id" : "8a8080fe663385cc016633a181b22ca7", "createdBy" : "8a8080cf65e02c0f0165e031fa6b0000", "createdDate" : "2018-10-02T07:15:14.482+0000", "modifiedBy" : "8a8080cf65e02c0f0165e031fa6b0000", "modifiedDate" : "2018-10-02T07:15:14.482+0000", "version" : null, "inactive" : false, "name" : "FX Issues", "region" : null, "accessKey" : null, "secretKey" : null, "org" : { "id" : "8a8080fe663385cc016633a181ae2ca4", "createdBy" : "8a8080cf65e02c0f0165e031fa6b0000", "createdDate" : "2018-10-02T07:15:14.478+0000", "modifiedBy" : "8a8080cf65e02c0f0165e031fa6b0000", "modifiedDate" : "2018-10-02T07:15:14.478+0000", "version" : null, "inactive" : false, "name" : "orgtest45" }, "accountType" : "FX_Issues", "prop1" : null, "prop2" : null, "prop3" : null, "allowedRegions" : [ ] } ], "totalPages" : 1, "totalElements" : 2 }

Logs :
Assertion [@StatusCode == 403] resolved-to [200 == 403] result [Failed] --- FX Bot ---

amjadafanah commented 6 years ago

Project : FX-SAAS-9

Job : Dev

Env : Dev

Region : FXLabs/US_WEST_1

Result : fail

Status Code : 401

Headers : {WWW-Authenticate=[Basic realm="Realm"], X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Thu, 04 Oct 2018 11:10:51 GMT]}

Endpoint : http://13.56.210.25/api/v1/accounts/search

Request :

Response :
{ "timestamp" : "2018-10-04T11:10:51.447+0000", "status" : 401, "error" : "Unauthorized", "message" : "Unauthorized", "path" : "/api/v1/accounts/search" }

Logs :
Assertion [@StatusCode == 403] resolved-to [401 == 403] result [Failed] --- FX Bot ---