Repository navigation
Fix ASP.NET WebForms issues in AdPentest.aspx - #72
Open
netanelcyber wants to merge 11 commits into
Open
netanelcyber wants to merge 11 commits into
netanelcyber wants to merge 11 commits into
Conversation
feat: Jinja2-based interactive HTML pentest report generator (Closes #22)
Brings over AdPentest.aspx from the earlier session branch (claude/eager-cray-4gl5be) with correct Page directive and assembly references: EntityFramework, System.Data.SQLite, System.Data.SQLite.EF6, Newtonsoft.Json, and System.ComponentModel.DataAnnotations. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DQhrDWE9kCvwRXjg9dNLGC
- Include target in CVE dedup key so multi-host findings are not collapsed - Validate CVE match entries are JObject before indexing - Allow PopulateReport on truncated output (JSON may still be valid) - Observe cancellation token to stop scan on app pool recycle - Add fallbacks for target/mode fields to accept older report formats - Fix confidence caption from "all low" to "low- to medium-confidence" Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DQhrDWE9kCvwRXjg9dNLGC
- Validate Host header (localhost/127.0.0.1/[::1]) to block DNS-rebinding attacks against the IsLocal-only page - Guard exit-code status assignment with !cancelled so "cancelled" status is not overwritten by "completed"/"failed"/"output-truncated" - Check activeSearch is JObject before indexing into it Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DQhrDWE9kCvwRXjg9dNLGC
- DrainAsync now reads up to 4 MiB (MaxParseChars) for report parsing while still capping the DB-stored display at 512 KiB, so large JSON reports are parsed correctly even when display output is truncated - run_id is now optional in PopulateReport so sample/imported JSON without a run_id can be imported successfully - When QueueBackgroundWorkItem fails, update the DB row from "queued" to "error" so it does not mislead operators Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DQhrDWE9kCvwRXjg9dNLGC
The row variable was declared inside try, making row.Id unreachable in the catch block. Moved rowId declaration before try and added a guard (rowId > 0) so the error-status update only runs after a successful DB insert. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DQhrDWE9kCvwRXjg9dNLGC
- output-truncated status only replaces "completed", preserving "failed" and "timeout" statuses when output is also truncated - Target field in PopulateReport is now optional; falls back to row.RequestedTarget so CLI error reports without a target field are accepted - Port list caption in Hebrew and English now matches the actual ports scanned by active_service_search in core.py Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DQhrDWE9kCvwRXjg9dNLGC
…mode - stream-timeout no longer overwrites cancelled/timeout status - PopulateReport runs whenever stdout completed, even during stream-timeout (stderr-only timeout no longer blocks parsing) - Mode falls back to row.Mode for targetless error reports Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DQhrDWE9kCvwRXjg9dNLGC
Add ASP.NET Web Forms dashboard with verified page directives
- Remove deprecated EnableViewStateMac attribute (always enforced in .NET 4.5.2+) - Add System.Web.Hosting namespace import and use short type names - Fix fire-and-forget async in cancellation callback (discard Task explicitly instead of calling .ConfigureAwait(false) without await) - Fix double space in process arguments string - Fix UI text mismatch: active-search description said "careful" but command uses "full" - HTML-encode SeverityClass Eval in class attribute for defense-in-depth Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012UJccLLHHrsJxUjpLbcx56
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Requested by NETANEL · project thread
Before: The page carried a deprecated
EnableViewStateMacattribute, had an unobserved fire-and-forget async task in the cancellation callback, used fully-qualifiedSystem.Web.Hostingreferences inconsistently, had a double space in process arguments, displayed "careful" in the UI while the command used--active-search full, and left aSeverityClassEval unencoded in a class attribute.After: All six issues are resolved. The page directive is clean, the cancellation callback properly discards the Task, namespace usage is consistent, the argument string is correct, the UI text matches the actual command, and the severity class attribute is HTML-encoded for defense-in-depth.
The change removes a no-op attribute, adds one namespace import, and fixes five minor code/text issues — no behavioral change to the page.
How: Single-file edit to
AdPentest.aspxcovering the page directive, namespace imports, theRunScanBackgroundAsynccancellation registration, theProcessStartInfo.Argumentsstring, the UI description in both Hebrew and English, and the CVE GridView template field.🤖 Generated with Claude Code
https://claude.ai/code/session_012UJccLLHHrsJxUjpLbcx56
Generated by Claude Code