You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

添加认证脚本后OWASP ZAP-Advanced容器启动失败,无法执行DAST扫描

问题解决:secureCodeBox ZAP Advanced添加认证脚本后容器启动失败

问题分析

容器卡在ContainerCreating状态,结合你的配置,核心问题集中在YAML格式错误、认证脚本不符合ZAP规范、参数格式错误这几点:

  1. 扫描配置的YAML中,认证脚本的scripts块缩进异常,导致配置解析失败
  2. 你的认证脚本用了Node.js风格的node-fetch,但ZAP的Graal.js环境不支持Node.js模块,且未实现ZAP认证脚本要求的标准接口
  3. Scan资源中-t参数后的URL带多余空格,可能引发参数解析异常

修复步骤

1. 修正YAML配置缩进

调整zap-advanced-scan-config ConfigMap里的scripts块缩进,使其与apis、contexts同级(原配置缩进多了一个空格,导致YAML结构错误):

---
apiVersion: v1
kind: ConfigMap
metadata:
  name: zap-advanced-scan-config
data:
  2-zap-advanced-scan.yaml: |-

    global:
      sessionName: mybizservice-zap-api-scan
      scripts:
        - name: "Alert_on_HTTP_Response_Code_Errors.js"
          enabled: true
          filePath: "/home/zap/.ZAP_D/scripts/scripts/httpsender/Alert_on_HTTP_Response_Code_Errors.js"
          engine: "Oracle Nashorn"
          type: "httpsender"
          description: "A HTTP Sender Script which will raise alerts based on HTTP Response codes."
        - name: "Alert_on_Unexpected_Content_Types.js"
          enabled: true
          filePath: "/home/zap/.ZAP_D/scripts/scripts/httpsender/Alert_on_Unexpected_Content_Types.js"
          engine: "Oracle Nashorn"
          type: "httpsender"
          description: "A HTTP Sender Script which will raise alerts based on unexpected Content-Types."

    contexts:
      - name: mybizservice-context
        url: https://abc-dev.org.cloud/
        includePaths:
          - "https://abc-dev.org.cloud/backend/payment.*"
        excludePaths:
          - ".*\\.css"
          - ".*\\.png"
          - ".*\\.jpeg"

    apis:
      - name: scb-mybizservice-api
        context: mybizservice-context
        format: openapi
        url: https://abc-dev.org.cloud/backend/payment/v3/api-docs
        hostOverride: https://abc-dev.org.cloud

    scripts:
      - name: "zap-api-authentication-script"
        enabled: true
        filePath: "/home/zap/.ZAP_D/scripts/scripts/authentication/zap-api-authentication.js"
        engine: "Graal.js"
        type: "authentication"
        description: "ZAP API AuthN script for K8s"
                
    spiders:
      - name: mybizservice-spider
        context: mybizservice-context
        url: https://abc-dev.org.cloud/backend/payment/
        failIfFoundUrlsLessThan: 0
        warnIfFoundUrlsLessThan: 0
        maxDuration: 1
        maxDepth: 5
        maxChildren: 10
        acceptCookies: true
        parseComments: true
        parseGit: false
        parseRobotsTxt: false
        parseSitemapXml: false
        parseSVNEntries: false
        postForm: true
        processForm: true
        requestWaitTime: 200
        sendRefererHeader: true
        threadCount: 2
        userAgent: "secureCodeBox / ZAP Spider"
    
    scanners:
      - name: scb-mybizservice-scan
        context: mybizservice-context
        url: https://abc-dev.org.cloud/backend/payment/
        policy: "API-Minimal"
        default: 0 unlimited
        maxRuleDurationInMins: 1          
        maxScanDurationInMins: 5
        threadPerHost: 5
        delayInMs: 0
        addQueryParam: false
        handleAntiCSRFTokens: false
        injectPluginIdInHeader: false
        scanHeadersAllRequests: false

2. 重写符合ZAP规范的认证脚本

ZAP的Graal.js认证脚本必须实现authenticate()等标准方法,且需用Java原生HTTP工具(不能用Node.js模块)。以下是适配Client Credentials模式的正确脚本:

function getRequiredParams() {
    return [];
}

function getOptionalParams() {
    return [];
}

function authenticate(helper, params, credentials) {
    // 认证配置
    const clientId = "clientid1212";
    const clientSecret = "abcd1234-200f-4427-9c8c-48ef6789wxyz";
    const tokenUrl = "https://abc-dev.org.cloud/uaa/oauth/token";

    // 构建Basic Auth头
    const basicAuth = java.util.Base64.getEncoder().encodeToString((clientId + ":" + clientSecret).getBytes());
    
    // 构建请求体
    const formData = "grant_type=client_credentials";
    
    // 发送POST请求获取Token
    const url = new java.net.URL(tokenUrl);
    const conn = url.openConnection();
    conn.setRequestMethod("POST");
    conn.setRequestProperty("Content-Type", "application/x-www-form-urlencoded");
    conn.setRequestProperty("Authorization", "Basic " + basicAuth);
    conn.setDoOutput(true);
    
    const os = conn.getOutputStream();
    os.write(formData.getBytes());
    os.flush();
    os.close();
    
    // 读取并解析响应
    const is = conn.getInputStream();
    const reader = new java.io.BufferedReader(new java.io.InputStreamReader(is));
    let line;
    const response = [];
    while ((line = reader.readLine()) != null) {
        response.push(line);
    }
    reader.close();
    is.close();
    
    const json = JSON.parse(response.join(""));
    const accessToken = json.access_token;
    
    // 将Token添加到ZAP的认证头中
    helper.addAuthHeader("Authorization: Bearer " + accessToken);
    
    return true;
}

function getAuthParamNames() {
    return [];
}

function getCredentialsParamsNames() {
    return [];
}

把这个脚本替换到zap-api-authentication-script ConfigMap中。

3. 修正Scan资源的参数错误

去掉-t参数后URL前的多余空格:

apiVersion: "execution.securecodebox.io/v1"
kind: Scan
metadata:
  name: "zap-advanced-api-scan-mybizservice"
  labels:
    organization: "OWASP"
spec:
  scanType: "zap-advanced-scan"
  parameters:
    - "-t"
    - "https://abc-dev.org.cloud/backend/payment/"
    - "-o"
    - "/home/securecodebox/"
  volumeMounts:
    - name: zap-advanced-scan-config
      mountPath: /home/securecodebox/configs/2-zap-advanced-scan.yaml
      subPath: 2-zap-advanced-scan.yaml
      readOnly: true
    - name: zap-api-authentication-script
      mountPath: /home/zap/.ZAP_D/scripts/scripts/authentication/zap-api-authentication.js
      subPath: zap-api-authentication.js
  volumes:
    - name: zap-advanced-scan-config
      configMap:
        name: zap-advanced-scan-config
    - name: zap-api-authentication-script
      configMap:
        name: zap-api-authentication-script

4. 验证修复效果

重新应用所有配置:

kubectl apply -f zap-advanced-scan-config.yaml
kubectl apply -f zap-api-authentication-script.yaml
kubectl apply -f scan.yaml

查看Pod状态:

kubectl get pods

如果仍有问题,查看Pod事件排查细节:

kubectl describe pod <你的Pod名称>

额外提示

  • 确保集群网络策略允许ZAP容器访问认证服务器(https://abc-dev.org.cloud/uaa/oauth/token)
  • 扫描完成后,通过kubectl logs <你的Pod名称>查看ZAP日志,确认认证是否成功执行

内容的提问来源于stack exchange,提问作者Dhaval Simaria

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.18 00:57:04