*** davidjd-gh has joined #openstack-security | 00:28 | |
*** davidjd-gh has left #openstack-security | 00:28 | |
*** yuanying has quit IRC | 00:30 | |
*** davidjd-gh has joined #openstack-security | 00:48 | |
*** davidjd-gh has left #openstack-security | 00:49 | |
*** edtubill has joined #openstack-security | 00:54 | |
*** browne has quit IRC | 01:20 | |
*** unrahul has quit IRC | 01:22 | |
*** yuanying has joined #openstack-security | 01:36 | |
*** edtubill has quit IRC | 01:38 | |
*** vinaypotluri has quit IRC | 01:51 | |
*** yuanying has quit IRC | 02:03 | |
*** yuanying has joined #openstack-security | 02:03 | |
*** yuanying has quit IRC | 02:04 | |
*** yuanying has joined #openstack-security | 02:08 | |
*** yuanying has quit IRC | 02:12 | |
*** yuanying has joined #openstack-security | 02:14 | |
*** yuanying has quit IRC | 02:26 | |
*** dave-mccowan has quit IRC | 02:39 | |
*** deblike has quit IRC | 02:43 | |
*** markvoelker has quit IRC | 02:45 | |
*** sdake has joined #openstack-security | 02:59 | |
*** yuanying has joined #openstack-security | 03:13 | |
*** yuanying has quit IRC | 03:18 | |
*** yuanying has joined #openstack-security | 03:18 | |
*** yuanying has quit IRC | 03:23 | |
*** markvoelker has joined #openstack-security | 03:39 | |
*** yuanying has joined #openstack-security | 03:59 | |
*** eric_lopez has joined #openstack-security | 04:18 | |
*** elo has quit IRC | 04:21 | |
*** yuanying has quit IRC | 04:58 | |
*** austin987 has quit IRC | 05:08 | |
*** yuanying has joined #openstack-security | 05:08 | |
*** austin987 has joined #openstack-security | 05:09 | |
*** austin987 has quit IRC | 05:12 | |
*** sdake has quit IRC | 05:26 | |
*** markvoelker has quit IRC | 05:52 | |
*** yuanying has quit IRC | 05:56 | |
*** yuanying has joined #openstack-security | 05:58 | |
*** rcernin has joined #openstack-security | 06:01 | |
*** markvoelker has joined #openstack-security | 06:34 | |
*** liverpooler has joined #openstack-security | 06:38 | |
*** markvoelker has quit IRC | 06:39 | |
*** pcaruana has joined #openstack-security | 06:40 | |
*** rcernin has quit IRC | 07:05 | |
*** tesseract- has joined #openstack-security | 07:10 | |
*** rcernin has joined #openstack-security | 07:21 | |
*** markvoelker has joined #openstack-security | 07:28 | |
*** markvoelker has quit IRC | 07:35 | |
*** yuanying has quit IRC | 07:42 | |
*** yuanying has joined #openstack-security | 07:43 | |
*** liverpooler has quit IRC | 07:51 | |
*** liverpooler has joined #openstack-security | 07:51 | |
*** d0ugal has joined #openstack-security | 07:59 | |
*** rcernin has quit IRC | 08:00 | |
*** rcernin has joined #openstack-security | 08:13 | |
*** markvoelker has joined #openstack-security | 08:23 | |
*** markvoelker has quit IRC | 08:27 | |
*** yuanying has quit IRC | 08:31 | |
*** yuanying has joined #openstack-security | 08:37 | |
*** gszafranski has joined #openstack-security | 08:41 | |
*** gszafranski has quit IRC | 08:52 | |
*** gszafranski has joined #openstack-security | 08:52 | |
*** yuanying has quit IRC | 08:53 | |
*** aastha has quit IRC | 08:59 | |
*** markvoelker has joined #openstack-security | 09:17 | |
*** markvoelker has quit IRC | 09:21 | |
*** woodburn has quit IRC | 09:35 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/342071 | 09:47 |
---|---|---|
*** markvoelker has joined #openstack-security | 10:11 | |
*** markvoelker has quit IRC | 10:16 | |
*** gszafranski has quit IRC | 10:27 | |
*** gszafranski has joined #openstack-security | 10:28 | |
openstackgerrit | Merged openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/342071 | 10:56 |
*** gszafranski has quit IRC | 10:57 | |
*** markvoelker has joined #openstack-security | 11:05 | |
*** markvoelker has quit IRC | 11:09 | |
*** v12aml has quit IRC | 11:11 | |
*** dave-mccowan has joined #openstack-security | 11:41 | |
*** markvoelker has joined #openstack-security | 11:59 | |
*** markvoelker has quit IRC | 12:03 | |
*** _elmiko is now known as elmiko | 12:46 | |
*** d0ugal has quit IRC | 12:53 | |
*** edmondsw has joined #openstack-security | 13:06 | |
*** sdake__ has joined #openstack-security | 13:15 | |
*** cleong has joined #openstack-security | 13:30 | |
*** bigdogstl has joined #openstack-security | 13:31 | |
*** bigdogstl has quit IRC | 13:31 | |
*** ametts has joined #openstack-security | 13:33 | |
*** ninag has joined #openstack-security | 13:39 | |
*** ninag has quit IRC | 13:45 | |
*** ccneill has joined #openstack-security | 13:46 | |
*** woodburn has joined #openstack-security | 13:47 | |
*** datadog327 has joined #openstack-security | 13:47 | |
*** ametts has quit IRC | 13:54 | |
*** ccneill has quit IRC | 13:55 | |
*** ametts has joined #openstack-security | 14:07 | |
*** edmondsw has quit IRC | 14:10 | |
openstackgerrit | Tim Kelsey proposed openstack/bandit: Adding more plugin config docs https://review.openstack.org/341417 | 14:14 |
*** catintheroof has joined #openstack-security | 14:16 | |
*** aastha has joined #openstack-security | 14:19 | |
*** jmckind has joined #openstack-security | 14:20 | |
*** deblike has joined #openstack-security | 14:33 | |
*** markvoelker has joined #openstack-security | 14:35 | |
*** mvaldes has joined #openstack-security | 14:35 | |
*** zul has quit IRC | 14:36 | |
*** pcaruana has quit IRC | 14:39 | |
*** zul has joined #openstack-security | 14:40 | |
*** d0ugal has joined #openstack-security | 14:46 | |
*** edtubill has joined #openstack-security | 14:54 | |
*** mvaldes has quit IRC | 15:02 | |
*** edmondsw has joined #openstack-security | 15:05 | |
*** vinaypotluri has joined #openstack-security | 15:09 | |
*** d0ugal has quit IRC | 15:16 | |
*** d0ugal has joined #openstack-security | 15:17 | |
*** mvaldes has joined #openstack-security | 15:58 | |
*** mdong has joined #openstack-security | 16:03 | |
*** jmckind_ has joined #openstack-security | 16:09 | |
*** jmckind has quit IRC | 16:12 | |
*** sdake__ is now known as sdake | 16:20 | |
*** rcernin has quit IRC | 16:21 | |
*** d0ugal has quit IRC | 16:49 | |
*** mvaldes has quit IRC | 16:51 | |
*** tmcpeak has joined #openstack-security | 16:56 | |
*** unrahul has joined #openstack-security | 16:58 | |
*** tkelsey has joined #openstack-security | 17:00 | |
*** sdake has quit IRC | 17:00 | |
*** sdake has joined #openstack-security | 17:02 | |
*** jmckind_ has quit IRC | 17:03 | |
*** jmckind has joined #openstack-security | 17:05 | |
openstackgerrit | Merged openstack/security-doc: Adding OSSN-0068 https://review.openstack.org/313896 | 17:15 |
*** jmckind has quit IRC | 17:25 | |
*** rcernin has joined #openstack-security | 17:32 | |
*** browne has joined #openstack-security | 17:32 | |
*** sdake_ has joined #openstack-security | 17:42 | |
*** tesseract- has quit IRC | 17:44 | |
*** sdake has quit IRC | 17:44 | |
*** catintheroof has quit IRC | 17:58 | |
*** sdake has joined #openstack-security | 18:02 | |
*** jmckind has joined #openstack-security | 18:02 | |
*** sdake_ has quit IRC | 18:03 | |
*** tkelsey has quit IRC | 18:09 | |
*** sdake_ has joined #openstack-security | 18:16 | |
*** sdake has quit IRC | 18:18 | |
*** mvaldes has joined #openstack-security | 18:24 | |
*** eric_lopez has quit IRC | 18:41 | |
*** elo has joined #openstack-security | 18:42 | |
*** mvaldes has quit IRC | 18:48 | |
*** ccneill has joined #openstack-security | 18:56 | |
*** catintheroof has joined #openstack-security | 19:18 | |
*** sdake__ has joined #openstack-security | 19:19 | |
*** mvaldes has joined #openstack-security | 19:19 | |
*** sdake_ has quit IRC | 19:21 | |
*** sdake_ has joined #openstack-security | 19:25 | |
*** sdake__ has quit IRC | 19:28 | |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: Adding header checks and unit tests https://review.openstack.org/340211 | 19:32 |
*** jmckind_ has joined #openstack-security | 19:36 | |
*** davidjd-gh has joined #openstack-security | 19:39 | |
*** davidjd-gh has left #openstack-security | 19:40 | |
*** jmckind has quit IRC | 19:40 | |
unrahul | Hey ccneill you here? | 19:41 |
unrahul | Hey aastha, vinaypotluri can you please review https://review.openstack.org/340211 | 19:42 |
unrahul | ccneill: mdong for checks like content_type, should be check the test_resp too, i feel it would be an over head to do that.. unless there is a side effect due to the fuzz string.. as if we are checking test_resp each time, for some tests, it would be an overkill, what do you guys think..? | 19:44 |
*** davidjd-gh has joined #openstack-security | 20:00 | |
*** ametts has quit IRC | 20:00 | |
*** davidjd-gh has left #openstack-security | 20:00 | |
ccneill | unrahul: I think the key is making the checks light-weight enough that the overhead is negligible | 20:02 |
ccneill | unrahul: we should only do the check on the init_resp one time so that we're not just wasting time there | 20:02 |
ccneill | unrahul: but an example might be if you submit a string that crashes the app and the webserve responds with a 500; so init_resp might have a JSON content type, and then test_resp has an HTML content type | 20:03 |
ccneill | I think most of our overhead at this point is in waiting for the HTTP req/resp to happen, and then spitting out our results log | 20:04 |
*** tkelsey has joined #openstack-security | 20:04 | |
unrahul | Mm.. Yeah that is a possible situation where the checks matter | 20:05 |
*** tkelsey has quit IRC | 20:09 | |
*** jmckind_ has quit IRC | 20:14 | |
*** ametts has joined #openstack-security | 20:15 | |
*** jmckind has joined #openstack-security | 20:16 | |
*** datadog327 has quit IRC | 20:35 | |
ccneill | I think we want to make as few of those decisions as possible. we don't want an endless list of checks, but at the same time, with APIs, there's really only so much info you can glean from any given req/resp | 20:37 |
ccneill | so I think a canonical set of checks every time should be reasonable. if we find that the performance hit is too much, we can always revise | 20:37 |
ccneill | (e.g. status code, content type) | 20:37 |
ccneill | unrahul, mdong, vinaypotluri, aastha: some thoughts on signal convenience methods: https://gist.github.com/cneill/d004a865f5bfd5ad056fbf86184ba16a | 20:38 |
ccneill | just a couple ideas I had | 20:38 |
ccneill | also added a bunch of action items for logging: https://gist.github.com/cneill/d004a865f5bfd5ad056fbf86184ba16a | 20:40 |
ccneill | unrahul: I deleted the task that was assigned to you that was basically "do logging" and broke it into smaller sub-tasks | 20:41 |
*** davidjd-gh has joined #openstack-security | 20:42 | |
*** v12aml has joined #openstack-security | 20:42 | |
*** davidjd-gh has left #openstack-security | 20:47 | |
unrahul | ccneill: was in a meeting, just seeing all these ping.. | 20:49 |
*** deblike has quit IRC | 20:51 | |
unrahul | Hey ccneill was it a second gist | 20:52 |
unrahul | ? | 20:52 |
unrahul | i think u posted the same gist.. twice.. | 20:53 |
unrahul | ? | 20:53 |
*** davidjd-gh1 has joined #openstack-security | 20:57 | |
*** davidjd-gh1 has left #openstack-security | 20:58 | |
*** mdong has quit IRC | 20:58 | |
*** mdong has joined #openstack-security | 21:00 | |
*** davidjd-gh has joined #openstack-security | 21:03 | |
*** davidjd-gh has left #openstack-security | 21:04 | |
ccneill | ah, oops | 21:05 |
ccneill | I meant to link the trello board on the second one | 21:05 |
ccneill | https://trello.com/c/jH4gDppe/27-sectest-syn-remove-opencafe-from-syntribos | 21:05 |
openstackgerrit | Merged openstack/syntribos: Adding header checks and unit tests https://review.openstack.org/340211 | 21:06 |
ccneill | unrahul: re: your comments on this CR https://review.openstack.org/#/c/340602/ | 21:06 |
ccneill | we may make different sets of "default checks" based on the type of test | 21:07 |
ccneill | I think that makes sense | 21:07 |
ccneill | so we might have a basic set for BTC, a few more for BFTC, and then whatever you want for other test types | 21:07 |
*** edtubill has quit IRC | 21:20 | |
*** rcernin has quit IRC | 21:24 | |
*** cleong has quit IRC | 21:26 | |
openstackgerrit | Michael Dong proposed openstack/syntribos: Refactored Auth test https://review.openstack.org/340477 | 21:37 |
*** catintheroof has quit IRC | 21:40 | |
unrahul | okay ccneill .. that makes sense.. | 21:52 |
unrahul | I shall update the checks to enable things like that. | 21:52 |
*** edmondsw has quit IRC | 21:52 | |
unrahul | ls | 21:54 |
unrahul | ! wrong window! | 21:54 |
openstack | unrahul: Error: "wrong" is not a valid command. | 21:54 |
*** ametts has quit IRC | 22:01 | |
*** ccneill has quit IRC | 22:02 | |
*** openstackgerrit has quit IRC | 22:03 | |
*** openstackgerrit has joined #openstack-security | 22:03 | |
*** elo has quit IRC | 22:09 | |
*** elo has joined #openstack-security | 22:09 | |
*** mvaldes has quit IRC | 22:12 | |
openstackgerrit | Merged openstack/bandit: Adding more plugin config docs https://review.openstack.org/341417 | 22:21 |
openstackgerrit | Eric Brown proposed openstack/bandit: Remove discover from test-requirements https://review.openstack.org/342455 | 22:31 |
*** mdong_ has joined #openstack-security | 22:49 | |
*** mdong has quit IRC | 22:51 | |
*** mdong_ is now known as mdong | 22:51 | |
*** ccneill has joined #openstack-security | 23:07 | |
*** jerrygb has joined #openstack-security | 23:08 | |
*** jmckind has quit IRC | 23:10 | |
openstackgerrit | Michael Dong proposed openstack/syntribos: Removed openCAFE dependencies from identity extension https://review.openstack.org/338403 | 23:20 |
openstackgerrit | Michael Dong proposed openstack/syntribos: Removed openCAFE dependencies from identity extension https://review.openstack.org/338403 | 23:23 |
*** jerrygb has quit IRC | 23:24 | |
openstackgerrit | Michael Dong proposed openstack/syntribos: Refactored Auth test https://review.openstack.org/340477 | 23:25 |
*** mdong has quit IRC | 23:28 | |
*** ccneill has quit IRC | 23:46 | |
*** tmcpeak has quit IRC | 23:50 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!