bcgov / bcgov/EDUC-STUDENT-DATA-COLLECTION-API
ZAP API Scan Report
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 2
- Forks
- 0
- PR merge metrics
- No merged PRs in 30d
Description
- Site: https://student-data-collection-api-d4cdde-test-dev.apps.silver.devops.gov.bc.ca
New Alerts- Content Security Policy (CSP) Header Not Set [10038] total: 1:
- A Server Error response code was returned by the server [100000] total: 68:
- https://student-data-collection-api-d4cdde-test-dev.apps.silver.devops.gov.bc.ca
- https://student-data-collection-api-d4cdde-test-dev.apps.silver.devops.gov.bc.ca/
- https://student-data-collection-api-d4cdde-test-dev.apps.silver.devops.gov.bc.ca/._darcs
- https://student-data-collection-api-d4cdde-test-dev.apps.silver.devops.gov.bc.ca/.bzr
- https://student-data-collection-api-d4cdde-test-dev.apps.silver.devops.gov.bc.ca/.DS_Store
- ..
- Strict-Transport-Security Header Not Set [10035] total: 1:
- Unexpected Content-Type was returned [100001] total: 70:
- https://student-data-collection-api-d4cdde-test-dev.apps.silver.devops.gov.bc.ca
- https://student-data-collection-api-d4cdde-test-dev.apps.silver.devops.gov.bc.ca/
- https://student-data-collection-api-d4cdde-test-dev.apps.silver.devops.gov.bc.ca/._darcs
- https://student-data-collection-api-d4cdde-test-dev.apps.silver.devops.gov.bc.ca/.bzr
- https://student-data-collection-api-d4cdde-test-dev.apps.silver.devops.gov.bc.ca/.DS_Store
- ..
- A Client Error response code was returned by the server [100000] total: 2:
View the following link to download the report.
RunnerID:9229115176
ZAP is supported by the Crash Override Open Source Fellowship
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Download the ZAP report from the linked GitHub Actions run and review the listed endpoints and alerts, especially the missing CSP and Strict-Transport-Security headers and the server or client error responses. Trace those responses to the API entry points and deployment configuration; done means the findings are understood, addressed, and the scan no longer reports the listed issues.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- api, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100