Commit 8d00ab6f authored by Michael Eddington's avatar Michael Eddington Committed by Russell Dickenson

Document _IMAGE_SUFFIX variable for API Security

parent 7f11b5b8
...@@ -586,7 +586,8 @@ profile increases as the number of tests increases. ...@@ -586,7 +586,8 @@ profile increases as the number of tests increases.
| CI/CD variable | Description | | CI/CD variable | Description |
|-------------------------------------------------------------|-------------| |-------------------------------------------------------------|-------------|
| `SECURE_ANALYZERS_PREFIX` | Specify the Docker registry base address from which to download the analyzer. | | `SECURE_ANALYZERS_PREFIX` | Specify the Docker registry base address from which to download the analyzer. |
| `FUZZAPI_VERSION` | Specify API Fuzzing container version. Defaults to `latest`. | | `FUZZAPI_VERSION` | Specify API Fuzzing container version. Defaults to `1`. |
| `FUZZAPI_IMAGE_SUFFIX` | Specify a container image suffix. Defaults to none. |
| `FUZZAPI_TARGET_URL` | Base URL of API testing target. | | `FUZZAPI_TARGET_URL` | Base URL of API testing target. |
| `FUZZAPI_CONFIG` | [Deprecated](https://gitlab.com/gitlab-org/gitlab/-/issues/276395) in GitLab 13.12, replaced with default `.gitlab/gitlab-api-fuzzing-config.yml`. API Fuzzing configuration file. | | `FUZZAPI_CONFIG` | [Deprecated](https://gitlab.com/gitlab-org/gitlab/-/issues/276395) in GitLab 13.12, replaced with default `.gitlab/gitlab-api-fuzzing-config.yml`. API Fuzzing configuration file. |
|[`FUZZAPI_PROFILE`](#api-fuzzing-profiles) | Configuration profile to use during testing. Defaults to `Quick-10`. | |[`FUZZAPI_PROFILE`](#api-fuzzing-profiles) | Configuration profile to use during testing. Defaults to `Quick-10`. |
...@@ -920,7 +921,7 @@ def get_auth_response(): ...@@ -920,7 +921,7 @@ def get_auth_response():
# In our example, access token is retrieved from a given endpoint # In our example, access token is retrieved from a given endpoint
try: try:
# Performs a http request, response sample: # Performs a http request, response sample:
# { "Token" : "b5638ae7-6e77-4585-b035-7d9de2e3f6b3" } # { "Token" : "b5638ae7-6e77-4585-b035-7d9de2e3f6b3" }
response = get_auth_response() response = get_auth_response()
...@@ -950,7 +951,7 @@ except Exception as e: ...@@ -950,7 +951,7 @@ except Exception as e:
logging.error(f'Error, unknown error while retrieving access token. Error message: {e}') logging.error(f'Error, unknown error while retrieving access token. Error message: {e}')
raise raise
# computes object that holds overrides file content. # computes object that holds overrides file content.
# It uses data fetched from request # It uses data fetched from request
overrides_data = { overrides_data = {
"headers": { "headers": {
......
...@@ -537,7 +537,9 @@ can be added, removed, and modified by creating a custom configuration. ...@@ -537,7 +537,9 @@ can be added, removed, and modified by creating a custom configuration.
| CI/CD variable | Description | | CI/CD variable | Description |
|------------------------------------------------------|--------------------| |------------------------------------------------------|--------------------|
| `DAST_API_VERSION` | Specify DAST API container version. Defaults to `latest`. | | `SECURE_ANALYZERS_PREFIX` | Specify the Docker registry base address from which to download the analyzer. |
| `DAST_API_VERSION` | Specify DAST API container version. Defaults to `1`. |
| `DAST_API_IMAGE_SUFFIX` | Specify a container image suffix. Defaults to none. |
| `DAST_API_TARGET_URL` | Base URL of API testing target. | | `DAST_API_TARGET_URL` | Base URL of API testing target. |
|[`DAST_API_CONFIG`](#configuration-files) | DAST API configuration file. Defaults to `.gitlab-dast-api.yml`. | |[`DAST_API_CONFIG`](#configuration-files) | DAST API configuration file. Defaults to `.gitlab-dast-api.yml`. |
|[`DAST_API_PROFILE`](#configuration-files) | Configuration profile to use during testing. Defaults to `Quick`. | |[`DAST_API_PROFILE`](#configuration-files) | Configuration profile to use during testing. Defaults to `Quick`. |
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment