feat(evidence): allow .exe uploads for Red-team artifacts shared with Blue
Aegis CI / lint-and-test (push) Has been cancelled
Snyk Security Scan / Python vulnerabilities (backend) (push) Has been cancelled
Snyk Security Scan / npm vulnerabilities (frontend) (push) Has been cancelled
Snyk Security Scan / Docker image vulnerabilities (backend) (push) Has been cancelled

The evidence upload extension whitelist blocked .exe entirely, but sharing
a Red team payload binary with Blue for detection analysis is a normal
part of this platform's workflow.
This commit is contained in:
kitos
2026-07-27 14:40:45 +02:00
parent 8985eeaa03
commit 99e8feff48
2 changed files with 30 additions and 0 deletions
+2
View File
@@ -57,6 +57,8 @@ ALLOWED_EXTENSIONS: frozenset[str] = frozenset({
".zip", ".tar", ".gz", ".7z",
# Literal argument value
".har", ".eml", ".msg",
# Red team artifacts shared with Blue for detection analysis.
".exe",
})
@@ -0,0 +1,28 @@
"""Evidence upload file-type validation — Red team artifacts (e.g. .exe
payloads) must be shareable with Blue for detection analysis."""
import pytest
from app.domain.errors import BusinessRuleViolation
from app.services.evidence_service import validate_file
def test_exe_files_are_allowed():
validate_file("payload.exe", 1024)
def test_allowed_extensions_still_pass():
for name in ("screenshot.png", "notes.pdf", "capture.pcap", "archive.zip"):
validate_file(name, 1024)
def test_disallowed_extension_still_rejected():
with pytest.raises(BusinessRuleViolation):
validate_file("script.sh", 1024)
def test_oversized_file_still_rejected():
from app.services.evidence_service import MAX_UPLOAD_SIZE
with pytest.raises(BusinessRuleViolation):
validate_file("payload.exe", MAX_UPLOAD_SIZE + 1)