Documentation
¶
Overview ¶
Package dastrunner executes narrowly-scoped, approved runtime verification probes.
This is not an autonomous exploit engine. The service only accepts a safety.AdmittedAction, which can be produced by safety.Gate after scope/window/RoE and HITL approval. It then runs a bounded, argv-only, safe HTTP probe, seals a compact result summary, and hands the typed proof class to dastverifier.Service / analysis.Verify for custody and score movement.
Index ¶
Constants ¶
const ( ToolRunDASTVerifier = "run_dast_verifier" ActionSafeHTTPProbe = "dast.safe_http_probe" )
Variables ¶
This section is empty.
Functions ¶
func ValidateURL ¶ added in v0.2.0
ValidateURL rejects a malformed or credential-bearing DAST target URL. It is the single source of truth for probe-target validation, enforced at both edges: when a run is submitted (before the probe is persisted on the durable job) and again inside the governed workflow before execution. Rejecting at submit keeps a credential-like URL (e.g. ?token=...) out of the durable jobs payload at rest.
Types ¶
type Result ¶
type Result struct {
Judgment judgment.Judgment
Proof dastverifier.ProofClass
Status int
Evidence shared.ID
}