Skip to content

add IAST code injection tests for java - #7445

Merged
claponcet merged 9 commits into
mainfrom
clara.poncet/java-iast-code-injection
Aug 11, 2026
Merged

add IAST code injection tests for java#7445
claponcet merged 9 commits into
mainfrom
clara.poncet/java-iast-code-injection

Conversation

@claponcet

@claponcet claponcet commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Motivation

The IAST CODE_INJECTION sink was not covered by system-tests for the Java tracer. This adds the weblog endpoints and enables the existing test_code_injection.py tests so the Java library's code-injection detection (BeanShell sink) is validated end-to-end.

Changes

  • Add a shared CodeInjectionExamples helper in iast-common that triggers the sink by evaluating input through BeanShell (bsh.Interpreter.eval), with an insecure (tainted input) and secure (hardcoded literal) variant.
  • Expose POST /iast/code_injection/test_insecure and POST /iast/code_injection/test_secure in the weblogs that carry the full IAST sink surface: akka-http, jersey-grizzly2, resteasy-netty3, spring-boot, vertx3, vertx4.
  • Add the bsh dependency to iast-common (optional) and to each weblog that implements the endpoint.
  • Enable TestCodeInjection and TestCodeInjection_StackTrace in manifests/java.yml from v1.66.0-SNAPSHOT:
    • play / ratpack: incomplete_test_app (endpoint not implemented) — these weblogs do not implement the IAST sink endpoints.
    • spring-boot-3-native: irrelevant (GraalVM. Tracing support only).

Workflow

  1. ⚠️ Create your PR as draft ⚠️
  2. Work on you PR until the CI passes
  3. Mark it as ready for review
    • Test logic is modified? -> Get a review from RFC owner.
    • Framework is modified, or non obvious usage of it -> get a review from R&P team

🚀 Once your PR is reviewed and the CI green, you can merge it!

🛟 #apm-shared-testing 🛟

Reviewer checklist

  • Anything but tests/ or manifests/ is modified ? I have the approval from R&P team
  • A docker base image is modified?
    • the relevant build-XXX-image label is present
  • A scenario is added, removed or renamed?

@github-actions

github-actions Bot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

CODEOWNERS have been resolved as:

utils/build/docker/java/iast-common/src/main/java/com/datadoghq/system_tests/iast/utils/CodeInjectionExamples.java  @DataDog/apm-java @DataDog/asm-java @DataDog/system-tests-core
manifests/java.yml                                                      @DataDog/asm-java @DataDog/apm-java
tests/appsec/iast/sink/test_code_injection.py                           @DataDog/asm-libraries @DataDog/system-tests-core
utils/build/docker/java/akka-http/pom.xml                               @DataDog/apm-java @DataDog/asm-java @DataDog/system-tests-core
utils/build/docker/java/akka-http/src/main/scala/com/datadoghq/akka_http/IastRoutes.scala  @DataDog/apm-java @DataDog/asm-java @DataDog/system-tests-core
utils/build/docker/java/iast-common/pom.xml                             @DataDog/apm-java @DataDog/asm-java @DataDog/system-tests-core
utils/build/docker/java/jersey-grizzly2/pom.xml                         @DataDog/apm-java @DataDog/asm-java @DataDog/system-tests-core
utils/build/docker/java/jersey-grizzly2/src/main/java/com/datadoghq/jersey/IastSinkResource.java  @DataDog/apm-java @DataDog/asm-java @DataDog/system-tests-core
utils/build/docker/java/play/pom.xml                                    @DataDog/apm-java @DataDog/asm-java @DataDog/system-tests-core
utils/build/docker/java/ratpack/pom.xml                                 @DataDog/apm-java @DataDog/asm-java @DataDog/system-tests-core
utils/build/docker/java/resteasy-netty3/pom.xml                         @DataDog/apm-java @DataDog/asm-java @DataDog/system-tests-core
utils/build/docker/java/resteasy-netty3/src/main/java/com/datadoghq/resteasy/IastSinkResource.java  @DataDog/apm-java @DataDog/asm-java @DataDog/system-tests-core
utils/build/docker/java/spring-boot/pom.xml                             @DataDog/apm-java @DataDog/asm-java @DataDog/system-tests-core
utils/build/docker/java/spring-boot/src/main/java/com/datadoghq/system_tests/springboot/AppSecIast.java  @DataDog/apm-java @DataDog/asm-java @DataDog/system-tests-core
utils/build/docker/java/vertx3/pom.xml                                  @DataDog/apm-java @DataDog/asm-java @DataDog/system-tests-core
utils/build/docker/java/vertx3/src/main/java/com/datadoghq/vertx3/iast/routes/IastSinkRouteProvider.java  @DataDog/apm-java @DataDog/asm-java @DataDog/system-tests-core
utils/build/docker/java/vertx4/pom.xml                                  @DataDog/apm-java @DataDog/asm-java @DataDog/system-tests-core
utils/build/docker/java/vertx4/src/main/java/com/datadoghq/vertx4/iast/routes/IastSinkRouteProvider.java  @DataDog/apm-java @DataDog/asm-java @DataDog/system-tests-core
utils/build/docker/java_otel/spring-boot/pom.xml                        @DataDog/opentelemetry @DataDog/system-tests-core

@datadog-prod-us1-5

datadog-prod-us1-5 Bot commented Aug 4, 2026

Copy link
Copy Markdown

Pipelines  Tests

⚠️ Warnings

🚦 2 Pipeline jobs failed

Testing the test | System Tests (php, dev) / End-to-end #2 / laravel11x 2   View in Datadog   GitHub Actions

See error 1 failed test. Assertion Error at tests/appsec/test_asm_standalone.py:250: assertion failed.

🧪 1 Test failed · 🎯 related to the job error above

🎯 ❄️ Known flaky: tests.appsec.test_asm_standalone.Test_APISecurityStandalone.test_no_appsec_upstream__no_asm_event__is_kept_with_priority_1__from_1[laravel11x] from system_tests_suite   View in Datadog
AssertionError: assert False
 +  where False = assert_tags(<utils.dd_types._datadog_library_trace.DataDogLibrarySpanLegacy object at 0x7f50bdaad640>, <utils.dd_types._datadog_library_trace.DataDogLibrarySpanLegacy object at 0x7f50bdaad640>, 'meta', {'_dd.p.other': '1', '_dd.p.ts': None})

self = <tests.appsec.test_asm_standalone.Test_APISecurityStandalone object at 0x7f50e1d96000>

    def test_no_appsec_upstream__no_asm_event__is_kept_with_priority_1__from_1(self):
        self.assert_product_is_enabled(self.check_r, self.tested_product)
        spans_checked = 0
        tested_meta: dict[str, str | Callable | None] = {self.propagated_tag(): None, "_dd.p.other": "1"}
        tested_metrics: dict[str, str | Callable | None] = {SAMPLING_PRIORITY_KEY: lambda x: x < 2}
...

Not introduced in this PR.

Testing the test | all-jobs-are-green   View in Datadog   GitHub Actions

See error Multiple system tests failed across various environments: java_lambda, dotnet, php, and java.

ℹ️ Info

No other issues found (see more)

❄️ No new flaky tests detected

Useful? React with 👍 / 👎

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: 2d16bac | Docs | Datadog PR Page | Give us feedback!

@claponcet
claponcet marked this pull request as ready for review August 5, 2026 13:43
@claponcet
claponcet requested review from a team as code owners August 5, 2026 13:43

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 2dac0de616

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

@claponcet
claponcet requested a review from a team as a code owner August 5, 2026 15:12
@claponcet
claponcet requested a review from peschinskiy August 5, 2026 15:12

@nccatoni nccatoni left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM (for @DataDog/system-tests-core) but you should get a review from someone more familiar with the feature and the tracer

@jandro996 jandro996 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed with Claude + an independent Codex pass (read-only, no edits). No blocking findings — CI is green and the implementation correctly follows dd-trace-java's method-advice contract for BeanShell (Interpreter.eval(String), matching sink #12113). Two minor notes:

  1. Non-blocking — see inline comment on manifests/java.yml about a missing location_map["java"] entry in test_code_injection.py.
  2. Nit — the PR description says tests are enabled "from v1.65.0-SNAPSHOT", but the manifests/java.yml diff actually targets v1.66.0-SNAPSHOT. Likely a stale description from a rebase — worth a quick update for anyone using the description as a changelog reference.

Also confirmed: the earlier bot comment about the missing bsh dependency in java_otel/spring-boot's pom.xml is already resolved by the tip commit (89915c1c8).

Comment thread manifests/java.yml

@jandro996 jandro996 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@claponcet
claponcet requested a review from a team as a code owner August 10, 2026 12:27
@claponcet
claponcet enabled auto-merge (squash) August 10, 2026 12:30
@claponcet
claponcet merged commit 5dc5af5 into main Aug 11, 2026
1389 of 1394 checks passed
@claponcet
claponcet deleted the clara.poncet/java-iast-code-injection branch August 11, 2026 13:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants