Automate OAuth access token for Zed Attack Proxy Scans

南楼画角 提交于 2019-12-12 05:58:50

问题


I want to run security scans for few REST APIs. These APIs use OAuth and are divided into two sets each using different Grant Type.

I want to run security scan using ZAP tool and I am not able to automate the process of getting OAuth Token used by the requests.

I am using SoapUI to record the APIs in ZAP which works very fine. But when the token expires, I have to re-record or edit token manually after retrieving it using SoapUI or PostMan.

A kind request to provide steps in little bit detail.

Please let me know if more details are required.

Any help will be really appreciated


回答1:


I was able to find the solution for this. Posting the solution here as well, please refer following URL:

https://groups.google.com/forum/#!searchin/zaproxy-users/Sam%7Csort:relevance/zaproxy-users/HJZ8gxk17M8/5WQuD7t3AAAJ



来源:https://stackoverflow.com/questions/37925008/automate-oauth-access-token-for-zed-attack-proxy-scans

易学教程内所有资源均来自网络或用户发布的内容,如有违反法律规定的内容欢迎反馈
该文章没有解决你所遇到的问题?点击提问,说说你的问题,让更多的人一起探讨吧!