cisagov / ScubaGoggles

SCuBA Security Configuration Baselines and assessment tool for Google Workspace
https://www.cisa.gov/resources-tools/services/secure-cloud-business-applications-scuba-project
Creative Commons Zero v1.0 Universal
128 stars 13 forks source link

Drive/Docs 2.X - First Time Change Not Captured in Output #282

Open LaurenBassett opened 1 month ago

LaurenBassett commented 1 month ago

🐛 Summary

What's wrong? Please be specific.

If the setting is changed from the default in Drive/Docs 2.4, the first change is not captured by the tool. This occurs only when overriding the setting for the first time. Subsequent changes are captured by the tool.

To reproduce

Steps to reproduce the behavior:

  1. Navigate to Sharing Settings for Drive and Docs
  2. Select the 'Shared Drive Creation' setting
  3. Choose an OU from the side bar
  4. Check the box 'Allow viewers and commenters to download, print, and copy files'
  5. Click "Override"
  6. Run the Goggles tool, this OU will NOT show as non-compliant
  7. Then, uncheck the box, save the settings, recheck the box
  8. Run the tool again
  9. This time, the baseline will show as non-compliant, and the OU will be listed in the output.
Screenshot 2024-05-15 at 4 14 07 PM

Expected behavior

What did you expect to happen that didn't?

It should show the non-compliant OU as they are generated

LaurenBassett commented 1 month ago

Confirming this is also happening with 2.1 Confirming this happens with groups as well..