add IAST code injection tests for java - #7445
Conversation
|
|
|
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2dac0de616
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
nccatoni
left a comment
There was a problem hiding this comment.
LGTM (for @DataDog/system-tests-core) but you should get a review from someone more familiar with the feature and the tracer
jandro996
left a comment
There was a problem hiding this comment.
Reviewed with Claude + an independent Codex pass (read-only, no edits). No blocking findings — CI is green and the implementation correctly follows dd-trace-java's method-advice contract for BeanShell (Interpreter.eval(String), matching sink #12113). Two minor notes:
- Non-blocking — see inline comment on
manifests/java.ymlabout a missinglocation_map["java"]entry intest_code_injection.py. - Nit — the PR description says tests are enabled "from v1.65.0-SNAPSHOT", but the
manifests/java.ymldiff actually targetsv1.66.0-SNAPSHOT. Likely a stale description from a rebase — worth a quick update for anyone using the description as a changelog reference.
Also confirmed: the earlier bot comment about the missing bsh dependency in java_otel/spring-boot's pom.xml is already resolved by the tip commit (89915c1c8).
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Motivation
The IAST
CODE_INJECTIONsink was not covered by system-tests for the Java tracer. This adds the weblog endpoints and enables the existingtest_code_injection.pytests so the Java library's code-injection detection (BeanShell sink) is validated end-to-end.Changes
CodeInjectionExampleshelper iniast-commonthat triggers the sink by evaluating input through BeanShell (bsh.Interpreter.eval), with an insecure (tainted input) and secure (hardcoded literal) variant.POST /iast/code_injection/test_insecureandPOST /iast/code_injection/test_securein the weblogs that carry the full IAST sink surface:akka-http,jersey-grizzly2,resteasy-netty3,spring-boot,vertx3,vertx4.bshdependency toiast-common(optional) and to each weblog that implements the endpoint.TestCodeInjectionandTestCodeInjection_StackTraceinmanifests/java.ymlfromv1.66.0-SNAPSHOT:play/ratpack:incomplete_test_app (endpoint not implemented)— these weblogs do not implement the IAST sink endpoints.spring-boot-3-native:irrelevant (GraalVM. Tracing support only).Workflow
🚀 Once your PR is reviewed and the CI green, you can merge it!
🛟 #apm-shared-testing 🛟
Reviewer checklist
tests/ormanifests/is modified ? I have the approval from R&P teambuild-XXX-imagelabel is present