Skip to content

Conversation

@kingthorin
Copy link
Member

@kingthorin kingthorin commented Nov 25, 2025

Identify candidate Session token source messages via the DB directly.

The new code takes 20% of the time for the same site load. New: 13234ms vs Old: 65197ms (13sec vs 65sec).

@psiinon
Copy link
Member

psiinon commented Nov 25, 2025

Logo
Checkmarx One – Scan Summary & Detailsbe6b3cb8-ad1d-4c89-83ac-379723b03ba2

New Issues (1)

Checkmarx found the following issues in this Pull Request

Severity Issue Source File / Package Checkmarx Insight
LOW Log_Forging /addOns/authhelper/src/main/java/org/zaproxy/addon/authhelper/AuthUtils.java: 1160
detailsMethod at line 1160 of /addOns/authhelper/src/main/java/org/zaproxy/addon/authhelper/AuthUtils.java gets user input from element getValue. This ...
ID: GoPzVFRt8f2kL4Z%2F3FMOvaIEAB4%3D
Attack Vector

Use @Checkmarx to reach out to us for assistance.

Just send a PR comment with @Checkmarx followed by a natural language request.

Examples: @Checkmarx how are you able to help me? @Checkmarx rescan this PR

@kingthorin kingthorin force-pushed the sess-mgmt branch 14 times, most recently from c95b2d9 to 25b4a05 Compare November 27, 2025 15:02
@kingthorin kingthorin force-pushed the sess-mgmt branch 2 times, most recently from c4d6d81 to 9156f81 Compare November 28, 2025 13:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants