From 03d93fa4835edc7a5f621bf24e5a4ea7461adf0e Mon Sep 17 00:00:00 2001 From: j3ssie Date: Sun, 15 Feb 2026 21:20:38 +0700 Subject: [PATCH] feat: improve asset IP mapping and add default vulnerability confidence - Auto-populate HostIP from host field when IP is detected - Set default vulnerability confidence to 'firm' if not specified - Skip API logging for Next.js static routes (_next prefix) --- internal/functions/db_functions.go | 12 ++++++++ internal/functions/db_functions_test.go | 38 +++++++++++++++++++++++++ pkg/server/server.go | 7 ++++- 3 files changed, 56 insertions(+), 1 deletion(-) diff --git a/internal/functions/db_functions.go b/internal/functions/db_functions.go index abfc25c..42b8397 100644 --- a/internal/functions/db_functions.go +++ b/internal/functions/db_functions.go @@ -2213,6 +2213,13 @@ func mapJSONToAsset(data map[string]interface{}, workspace, rawLine string) data asset.HostIP = v } + // NEW: If host field contains an IP and HostIP wasn't explicitly set, store it + if asset.HostIP == "" && asset.AssetValue != "" { + if net.ParseIP(asset.AssetValue) != nil { + asset.HostIP = asset.AssetValue + } + } + // DNS records - prefer "dns_records" key, fall back to "a" for httpx compat if aRecords, ok := data["dns_records"].([]interface{}); ok { var records []string @@ -2844,6 +2851,11 @@ func mapJSONToVuln(data map[string]interface{}, workspace, rawLine string) datab vuln.DetailHTTPResponse = v } + // Set default confidence to "firm" if not specified + if vuln.Confidence == "" { + vuln.Confidence = "firm" + } + return vuln } diff --git a/internal/functions/db_functions_test.go b/internal/functions/db_functions_test.go index 88e1342..c2182de 100644 --- a/internal/functions/db_functions_test.go +++ b/internal/functions/db_functions_test.go @@ -339,6 +339,44 @@ func TestMapJSONToAsset(t *testing.T) { assert.NotEmpty(t, asset.RawJsonData) } +func TestMapJSONToAsset_HostIPFromIPHost(t *testing.T) { + data := map[string]interface{}{ + "host": "143.92.73.100", + "url": "https://fms.example.com", + "status_code": float64(200), + } + + asset := mapJSONToAsset(data, "test-workspace", `{"host":"143.92.73.100"}`) + + assert.Equal(t, "https://fms.example.com", asset.AssetValue) + assert.Equal(t, "143.92.73.100", asset.HostIP) // NEW: IP should be stored +} + +func TestMapJSONToAsset_ExplicitHostIPPreferred(t *testing.T) { + data := map[string]interface{}{ + "host": "143.92.73.100", + "host_ip": "203.0.113.42", // Different IP + "url": "https://example.com", + } + + asset := mapJSONToAsset(data, "test-workspace", `{}`) + + assert.Equal(t, "203.0.113.42", asset.HostIP) // Explicit value wins + assert.Equal(t, "https://example.com", asset.AssetValue) +} + +func TestMapJSONToAsset_DomainHostNoChange(t *testing.T) { + data := map[string]interface{}{ + "host": "example.com", + "url": "https://example.com", + } + + asset := mapJSONToAsset(data, "test-workspace", `{}`) + + assert.Equal(t, "", asset.HostIP) // No IP detected + assert.Equal(t, "example.com", asset.AssetValue) +} + func TestMapJSONToVuln(t *testing.T) { data := map[string]interface{}{ "template-id": "test-vuln", diff --git a/pkg/server/server.go b/pkg/server/server.go index db6c3bb..e062adc 100644 --- a/pkg/server/server.go +++ b/pkg/server/server.go @@ -141,7 +141,12 @@ func New(cfg *config.Config, opts *Options) (*Server, error) { // Apply middleware app.Use(recover.New()) - app.Use(logger.New()) + app.Use(logger.New(logger.Config{ + Next: func(c *fiber.Ctx) bool { + // Skip logging for Next.js static routes + return strings.Contains(c.Path(), "_next") + }, + })) app.Use(cors.New(cors.Config{ AllowOriginsFunc: func(origin string) bool { // Reflect all origins - returns true to allow and echo back the origin