|
21 | 21 | from prowler.providers.azure.azure_provider import AzureProvider |
22 | 22 | from prowler.providers.gcp.gcp_provider import GcpProvider |
23 | 23 | from prowler.providers.github.github_provider import GithubProvider |
| 24 | +from prowler.providers.iac.iac_provider import IacProvider |
24 | 25 | from prowler.providers.kubernetes.kubernetes_provider import KubernetesProvider |
25 | 26 | from prowler.providers.m365.m365_provider import M365Provider |
26 | 27 | from prowler.providers.mongodbatlas.mongodbatlas_provider import MongodbatlasProvider |
@@ -114,6 +115,7 @@ class TestReturnProwlerProvider: |
114 | 115 | (Provider.ProviderChoices.GITHUB.value, GithubProvider), |
115 | 116 | (Provider.ProviderChoices.MONGODBATLAS.value, MongodbatlasProvider), |
116 | 117 | (Provider.ProviderChoices.ORACLECLOUD.value, OraclecloudProvider), |
| 118 | + (Provider.ProviderChoices.IAC.value, IacProvider), |
117 | 119 | ], |
118 | 120 | ) |
119 | 121 | def test_return_prowler_provider(self, provider_type, expected_provider): |
@@ -254,6 +256,72 @@ def test_get_prowler_provider_kwargs_with_mutelist(self): |
254 | 256 | expected_result = {**secret_dict, "mutelist_content": {"key": "value"}} |
255 | 257 | assert result == expected_result |
256 | 258 |
|
| 259 | + def test_get_prowler_provider_kwargs_iac_provider(self): |
| 260 | + """Test that IaC provider gets correct kwargs with repository URL.""" |
| 261 | + provider_uid = "https://github.com/org/repo" |
| 262 | + secret_dict = {"access_token": "test_token"} |
| 263 | + secret_mock = MagicMock() |
| 264 | + secret_mock.secret = secret_dict |
| 265 | + |
| 266 | + provider = MagicMock() |
| 267 | + provider.provider = Provider.ProviderChoices.IAC.value |
| 268 | + provider.secret = secret_mock |
| 269 | + provider.uid = provider_uid |
| 270 | + |
| 271 | + result = get_prowler_provider_kwargs(provider) |
| 272 | + |
| 273 | + expected_result = { |
| 274 | + "scan_repository_url": provider_uid, |
| 275 | + "oauth_app_token": "test_token", |
| 276 | + } |
| 277 | + assert result == expected_result |
| 278 | + |
| 279 | + def test_get_prowler_provider_kwargs_iac_provider_without_token(self): |
| 280 | + """Test that IaC provider works without access token for public repos.""" |
| 281 | + provider_uid = "https://github.com/org/public-repo" |
| 282 | + secret_dict = {} |
| 283 | + secret_mock = MagicMock() |
| 284 | + secret_mock.secret = secret_dict |
| 285 | + |
| 286 | + provider = MagicMock() |
| 287 | + provider.provider = Provider.ProviderChoices.IAC.value |
| 288 | + provider.secret = secret_mock |
| 289 | + provider.uid = provider_uid |
| 290 | + |
| 291 | + result = get_prowler_provider_kwargs(provider) |
| 292 | + |
| 293 | + expected_result = {"scan_repository_url": provider_uid} |
| 294 | + assert result == expected_result |
| 295 | + |
| 296 | + def test_get_prowler_provider_kwargs_iac_provider_ignores_mutelist(self): |
| 297 | + """Test that IaC provider does NOT receive mutelist_content. |
| 298 | +
|
| 299 | + IaC provider uses Trivy's built-in mutelist logic, so it should not |
| 300 | + receive mutelist_content even when a mutelist processor is configured. |
| 301 | + """ |
| 302 | + provider_uid = "https://github.com/org/repo" |
| 303 | + secret_dict = {"access_token": "test_token"} |
| 304 | + secret_mock = MagicMock() |
| 305 | + secret_mock.secret = secret_dict |
| 306 | + |
| 307 | + mutelist_processor = MagicMock() |
| 308 | + mutelist_processor.configuration = {"Mutelist": {"key": "value"}} |
| 309 | + |
| 310 | + provider = MagicMock() |
| 311 | + provider.provider = Provider.ProviderChoices.IAC.value |
| 312 | + provider.secret = secret_mock |
| 313 | + provider.uid = provider_uid |
| 314 | + |
| 315 | + result = get_prowler_provider_kwargs(provider, mutelist_processor) |
| 316 | + |
| 317 | + # IaC provider should NOT have mutelist_content |
| 318 | + assert "mutelist_content" not in result |
| 319 | + expected_result = { |
| 320 | + "scan_repository_url": provider_uid, |
| 321 | + "oauth_app_token": "test_token", |
| 322 | + } |
| 323 | + assert result == expected_result |
| 324 | + |
257 | 325 | def test_get_prowler_provider_kwargs_unsupported_provider(self): |
258 | 326 | # Setup |
259 | 327 | provider_uid = "provider_uid" |
|
0 commit comments