Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 10 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,15 @@
# Changelog

## Version 2.1.1 - YesWeHack Inactive Programs

### 🐛 Bug Fixes

- Exclude YesWeHack programs marked `archived` or `disabled` from synchronization, using both the program listing and detail response.
- Remove previously stored scopes for these programs on the next sync, so they no longer appear in `/`. The removal is recorded in history as a `remove_program` event.
- Update the CLI `version` command and HTTP User-Agent to report the current release.

---

## Version 2.1.0 - Generic HTTP Webhook Notifications

### ✨ Features
Expand Down
2 changes: 1 addition & 1 deletion config/settings.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ app:

# HTTP client configuration
http:
user_agent: "ScopesExtractor/2.0 (Ruby; +github.com/JoshuaMart/ScopesExtractor)"
user_agent: "ScopesExtractor/2.1.1 (Ruby; +github.com/JoshuaMart/ScopesExtractor)"
proxy: null # Optional: "http://proxy.example.com:8080"
timeout: 30 # seconds

Expand Down
2 changes: 1 addition & 1 deletion lib/scopes_extractor/cli.rb
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ def self.exit_on_failure?

desc 'version', 'Display version information'
def version
puts 'ScopesExtractor version 2.0.0'
puts 'ScopesExtractor version 2.1.1'
end

desc 'reset', 'Reset the database (WARNING: deletes all data)'
Expand Down
2 changes: 1 addition & 1 deletion lib/scopes_extractor/config.rb
Original file line number Diff line number Diff line change
Expand Up @@ -29,7 +29,7 @@ def http
end

def user_agent
http[:user_agent] || 'ScopesExtractor/2.0'
http[:user_agent] || 'ScopesExtractor/2.1.1'
end

def proxy
Expand Down
29 changes: 19 additions & 10 deletions lib/scopes_extractor/platforms/yeswehack/platform.rb
Original file line number Diff line number Diff line change
Expand Up @@ -67,22 +67,17 @@ def fetch_programs
fetcher = ProgramFetcher.new(@token)
raw_programs = fetcher.fetch_all

# Filter out VDP programs before fetching details
if Config.skip_vdp?('yeswehack')
raw_programs = raw_programs.reject do |raw|
if raw['vdp'] == true
ScopesExtractor.logger.debug "[YesWeHack] Skipping VDP program: #{raw['slug']}"
true
else
false
end
end
# Inactive programs must disappear from the fetched set so the sync
# removes their previously stored scopes as well.
raw_programs = raw_programs.reject do |raw|
skip_program?(raw)
end

raw_programs.filter_map do |raw|
# Fetch full details to get scopes
details = fetcher.fetch_details(raw['slug'])
next unless details
next if skip_program?(details)

begin
parse_program(details)
Expand All @@ -97,6 +92,20 @@ def fetch_programs

private

def skip_program?(data)
reason = if data['archived'] == true
'archived'
elsif data['disabled'] == true
'disabled'
elsif Config.skip_vdp?('yeswehack') && data['vdp'] == true
'VDP'
end
return false unless reason

ScopesExtractor.logger.debug "[YesWeHack] Skipping #{reason} program: #{data['slug']}"
true
end

def authenticate
return @token if @token

Expand Down
2 changes: 1 addition & 1 deletion spec/scopes_extractor/config_spec.rb
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@
describe 'http settings' do
describe '.user_agent' do
it 'returns the configured user agent' do
expect(described_class.user_agent).to include('ScopesExtractor/2.0')
expect(described_class.user_agent).to include('ScopesExtractor/2.1.1')
expect(described_class.user_agent).to include('Ruby')
expect(described_class.user_agent).to include('github.com')
end
Expand Down
25 changes: 25 additions & 0 deletions spec/scopes_extractor/platforms/yeswehack/platform_spec.rb
Original file line number Diff line number Diff line change
Expand Up @@ -121,6 +121,31 @@
expect(platform.fetch_programs).to eq([])
end

%w[archived disabled].each do |status|
it "skips #{status} programs before fetching their details" do
allow(program_fetcher).to receive(:fetch_all).and_return(
[{ 'slug' => 'inactive', status => true },
{ 'slug' => 'active', 'archived' => false, 'disabled' => false }]
)
allow(program_fetcher).to receive(:fetch_details).with('active').and_return(
'slug' => 'active', 'title' => 'Active', 'bounty' => true, 'scopes' => []
)

expect(program_fetcher).not_to receive(:fetch_details).with('inactive')
expect(platform.fetch_programs.map(&:slug)).to eq(['active'])
end

it "skips a program whose details mark it #{status}" do
allow(program_fetcher).to receive(:fetch_all).and_return([{ 'slug' => 'inactive' }])
allow(program_fetcher).to receive(:fetch_details).with('inactive').and_return(
'slug' => 'inactive', 'title' => 'Inactive', 'bounty' => true,
'scopes' => [], status => true
)

expect(platform.fetch_programs).to eq([])
end
end

context 'when already authenticated' do
it 'does not authenticate again' do
# First call authenticates
Expand Down
Loading