ZAP automation framework, how to use installed module ?

52 views
Skip to first unread message

Rop Ox41414141

unread,
Mar 14, 2022, 5:15:16 AM3/14/22
to OWASP ZAP User Group

I am trying to use the automation framework to perform some access control testing.

I have it working with the classic API without any issue, now I m trying to use the automation framework, I have use the module addOns to add AccessControl but now how can I use it in the workflow ?

Simon Bennetts

unread,
Mar 14, 2022, 6:27:28 AM3/14/22
to OWASP ZAP User Group
Hiya,

Its good to hear that you have found the Access Control add-on useful - we've actually had very little feedback on it so we were not sure how much it is being used.
Right now the Access Control add-on does not have Automation Framework support.
However I have added an Access Control jonb to the AF tracker: https://github.com/zaproxy/zaproxy/issues/6461

Cheers,

Simon

Rop Ox41414141

unread,
Mar 21, 2022, 1:41:11 AM3/21/22
to OWASP ZAP User Group
I think the access control module should have the following parameters
The expected HTTP code result (ex: 200, 302) and also a regex to find a particular pattern that indicates if a specific message is displayed when reaching an unauthorised URL (for i.e. "You do not have access to this page")
That would help the efficiency of the access control module :)

Simon Bennetts

unread,
Mar 21, 2022, 5:18:07 AM3/21/22
to OWASP ZAP User Group
Thanks - I've added your suggestions to https://github.com/zaproxy/zaproxy/issues/6461#issuecomment-1073667062 so they dont get lost.
Reply all
Reply to author
Forward
0 new messages