Automated Keycloak authetication and Scan application Zap
295 views
Skip to first unread message
Shalini Mishra
unread,
Mar 22, 2024, 4:12:51 AM3/22/24
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to ZAP User Group
Hi All,
I am trying use Zap for my web app which is using Keycloak for authentication , once authentication done it redirect to application. Requirement is zap scan automatically only with app url and credential but for that I need set proxy to browser and traverse the each pages.
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to ZAP User Group
Hi Shalini,
It looks like ZAP successfully authenticated to the app, but then the app didnt make enough requests in the background for ZAP to identify the session or a suitable verification URL.
Try again, but this time:
Increase the timeout, eg to 30 seconds
Once the browser has logged in start exploring the site
Hopefully that will give ZAP a chance to identify the info in needs.