You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

zap-api-scan.py无法加载options.prop中自定义请求头问题

ZAP扫描API请求头配置不生效的解决办法

问题场景

使用OWASP ZAP的Docker镜像扫描需要携带Authorization和X-api-key请求头的REST API端点,已在options.prop中配置这两个请求头,但执行扫描命令后返回401错误,配置未生效。

执行命令:

docker run -v $(pwd):/zap/wrk/:rw -t owasp/zap2docker-weekly zap-api-scan.py -t <API URL> -f openapi -z "-configfile /zap/wrk/options.prop"

原options.prop内容:

replacer.full_list(0).description=Authorization
 replacer.full_list(0).enabled=true replacer.full_list(0).matchtype=REQ_HEADER  
 replacer.full_list(0).matchstr=Authorization 
 replacer.full_list(0).regex=false 
 replacer.full_list(0).replacement=<Token>
 replacer.full_list(1).description=x-api-key
 replacer.full_list(1).enabled=true
 replacer.full_list(1).matchtype=REQ_HEADER
 replacer.full_list(1).matchstr=x-api-key
 replacer.full_list(1).regex=false
 replacer.full_list(1).replacement=<Value>

问题原因

  1. 配置文件格式错误:原配置中replacer.full_list(0).enabled=true和replacer.full_list(0).matchtype=REQ_HEADER写在同一行,导致ZAP无法正确解析该配置项,进而忽略了整个replacer规则。
  2. 挂载目录权限或路径问题:Docker容器对挂载的/zap/wrk目录无读取权限,或者配置文件路径传递有误,导致ZAP无法加载配置。

解决步骤

1. 修正配置文件格式

将每个配置项单独拆分到一行,确保格式规范。修正后的options.prop:

replacer.full_list(0).description=Authorization
replacer.full_list(0).enabled=true
replacer.full_list(0).matchtype=REQ_HEADER
replacer.full_list(0).matchstr=Authorization
replacer.full_list(0).regex=false
replacer.full_list(0).replacement=<Token>

replacer.full_list(1).description=x-api-key
replacer.full_list(1).enabled=true
replacer.full_list(1).matchtype=REQ_HEADER
replacer.full_list(1).matchstr=x-api-key
replacer.full_list(1).regex=false
replacer.full_list(1).replacement=<Value>

2. 验证命令参数与挂载权限

  • 确保当前目录权限足够,Docker容器能读取挂载的/zap/wrk目录下的文件。
  • 确认命令中-z "-configfile /zap/wrk/options.prop"的参数传递正确,容器内路径/zap/wrk/options.prop对应本地当前目录下的文件。

3. 替代方案:直接在命令中传递配置

如果配置文件仍不生效,可以跳过配置文件,直接在命令中通过-z参数传递replacer规则,示例:

docker run -v $(pwd):/zap/wrk/:rw -t owasp/zap2docker-weekly zap-api-scan.py -t <API URL> -f openapi \
-z "-replacer.full_list(0).description=Authorization \
-replacer.full_list(0).enabled=true \
-replacer.full_list(0).matchtype=REQ_HEADER \
-replacer.full_list(0).matchstr=Authorization \
-replacer.full_list(0).regex=false \
-replacer.full_list(0).replacement=<Token> \
-replacer.full_list(1).description=x-api-key \
-replacer.full_list(1).enabled=true \
-replacer.full_list(1).matchtype=REQ_HEADER \
-replacer.full_list(1).matchstr=x-api-key \
-replacer.full_list(1).regex=false \
-replacer.full_list(1).replacement=<Value>"

4. 验证配置生效

执行扫描前,可启动ZAP容器进入交互模式,检查replacer配置是否正确加载:

docker run -v $(pwd):/zap/wrk/:rw -it owasp/zap2docker-weekly bash
# 启动ZAP并加载配置
zap.sh -configfile /zap/wrk/options.prop
# 通过ZAP界面或API检查replacer规则是否存在

内容的提问来源于stack exchange,提问作者Abhijith

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.05 15:35:20