You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用ZAP扫描API(Swagger 2.0)遇连接超时与JWT认证问题求助

ZAP扫描API的两个问题求助

问题1:流水线中ZAP强制使用HTTP连接HTTPS API导致超时

通过OpenAPI.yaml文件在流水线中用ZAP扫描HTTPS协议的API,文件能成功加载,但扫描时出现连接超时。已在OpenAPI.yaml中添加https schemes,ZAP仍尝试用HTTP连接目标API。

流水线错误详情

API request successful
Failed to process the OpenAPI file
Response details:
{
  "importFile": [
    "Failed to access URL: http://msst.qa1.csqp.sl.com/api/v2/wbs/v0/answer-product/jobs/qa-weu-des-prod-testing-eu:job:testlarzac9 : org.zaproxy.addon.network.common.ZapSocketTimeoutException : Connect to http://msst.qa1.csqp.sl.com:80 [msst.qa1.csqp.sl.com/35.204.239.105] failed: connect timed out"
  ]
}

OpenAPI.yaml中的schemes配置

schemes:
  - http
  - https

流水线加载文件的PowerShell脚本

$load_oas_file = "$zap_url" + "/JSON/openapi/action/importFile/?" + "apikey=$($zap_key)" + "&file=$($OAS)" + "&target="
Write-Output "Calling - $($load_oas_file)"
Invoke-RestMethod -Method Get -Uri $load_oas_file  

问题2:本地ZAP加载OpenAPI文件时JWT验证失败,令牌配置疑问

本地ZAP加载同一OpenAPI文件时,出现JWT格式验证失败错误。但在Postman中添加正确的访问令牌后可正常调用API,不清楚如何在本地ZAP及流水线中配置该令牌。

本地ZAP错误详情

{
 "code": 16,
 "message": "JWT validation failed: Bad JWT format: should have 2 dots",
 "details": [
  {
   "@type": "type.googleapis.com/google.rpc.DebugInfo",
   "stackEntries": [],
   "detail": "auth"
  }
 ]
}

内容的提问来源于stack exchange,提问作者Sheeba Cross

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.21 09:07:16