Skip to content

Commit c38f4a9

Browse files
izarizar tarandach
andauthored
BREAKING CHANGE - removing sqldump - #295 (#301)
As discussed, we are removing this functionality since I am the only one that needed it and now i dont and the code was junk. Co-authored-by: izar tarandach <izar.tarandach@siriusxm.com>
1 parent cfc38f8 commit c38f4a9

7 files changed

Lines changed: 546 additions & 387 deletions

File tree

CHANGELOG.md

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,9 @@
1+
# Unreleased
2+
3+
## Breaking changes
4+
5+
- Removed SQLite dump functionality (`--sqldump` option) and associated `pydal` dependency
6+
17
# 1.2.0
28

39
## Breaking changes

README.md

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -75,15 +75,13 @@ lower overhead and more convenient alternative to the OCI container approach.
7575
All available arguments:
7676

7777
```text
78-
usage: tm.py [-h] [--sqldump SQLDUMP] [--debug] [--dfd] [--report REPORT]
78+
usage: tm.py [-h] [--debug] [--dfd] [--report REPORT]
7979
[--exclude EXCLUDE] [--seq] [--list] [--describe DESCRIBE]
8080
[--list-elements] [--json JSON] [--levels LEVELS [LEVELS ...]]
8181
[--stale_days STALE_DAYS]
8282
8383
optional arguments:
8484
-h, --help show this help message and exit
85-
--sqldump SQLDUMP dumps all threat model elements and findings into the
86-
named sqlite file (erased if exists)
8785
--debug print debug messages
8886
--dfd output DFD
8987
--report REPORT output report using the named template file (sample

docs/pytm/index.html

Lines changed: 455 additions & 321 deletions
Large diffs are not rendered by default.

docs/pytm/report_util.html

Lines changed: 31 additions & 61 deletions
Original file line numberDiff line numberDiff line change
@@ -2,18 +2,32 @@
22
<html lang="en">
33
<head>
44
<meta charset="utf-8">
5-
<meta name="viewport" content="width=device-width, initial-scale=1, minimum-scale=1" />
6-
<meta name="generator" content="pdoc 0.10.0" />
5+
<meta name="viewport" content="width=device-width, initial-scale=1, minimum-scale=1">
6+
<meta name="generator" content="pdoc3 0.11.6">
77
<title>pytm.report_util API documentation</title>
8-
<meta name="description" content="" />
9-
<link rel="preload stylesheet" as="style" href="https://cdnjs.cloudflare.com/ajax/libs/10up-sanitize.css/11.0.1/sanitize.min.css" integrity="sha256-PK9q560IAAa6WVRRh76LtCaI8pjTJ2z11v0miyNNjrs=" crossorigin>
10-
<link rel="preload stylesheet" as="style" href="https://cdnjs.cloudflare.com/ajax/libs/10up-sanitize.css/11.0.1/typography.min.css" integrity="sha256-7l/o7C8jubJiy74VsKTidCy1yBkRtiUGbVkYBylBqUg=" crossorigin>
11-
<link rel="stylesheet preload" as="style" href="https://cdnjs.cloudflare.com/ajax/libs/highlight.js/10.1.1/styles/github.min.css" crossorigin>
12-
<style>:root{--highlight-color:#fe9}.flex{display:flex !important}body{line-height:1.5em}#content{padding:20px}#sidebar{padding:30px;overflow:hidden}#sidebar > *:last-child{margin-bottom:2cm}.http-server-breadcrumbs{font-size:130%;margin:0 0 15px 0}#footer{font-size:.75em;padding:5px 30px;border-top:1px solid #ddd;text-align:right}#footer p{margin:0 0 0 1em;display:inline-block}#footer p:last-child{margin-right:30px}h1,h2,h3,h4,h5{font-weight:300}h1{font-size:2.5em;line-height:1.1em}h2{font-size:1.75em;margin:1em 0 .50em 0}h3{font-size:1.4em;margin:25px 0 10px 0}h4{margin:0;font-size:105%}h1:target,h2:target,h3:target,h4:target,h5:target,h6:target{background:var(--highlight-color);padding:.2em 0}a{color:#058;text-decoration:none;transition:color .3s ease-in-out}a:hover{color:#e82}.title code{font-weight:bold}h2[id^="header-"]{margin-top:2em}.ident{color:#900}pre code{background:#f8f8f8;font-size:.8em;line-height:1.4em}code{background:#f2f2f1;padding:1px 4px;overflow-wrap:break-word}h1 code{background:transparent}pre{background:#f8f8f8;border:0;border-top:1px solid #ccc;border-bottom:1px solid #ccc;margin:1em 0;padding:1ex}#http-server-module-list{display:flex;flex-flow:column}#http-server-module-list div{display:flex}#http-server-module-list dt{min-width:10%}#http-server-module-list p{margin-top:0}.toc ul,#index{list-style-type:none;margin:0;padding:0}#index code{background:transparent}#index h3{border-bottom:1px solid #ddd}#index ul{padding:0}#index h4{margin-top:.6em;font-weight:bold}@media (min-width:200ex){#index .two-column{column-count:2}}@media (min-width:300ex){#index .two-column{column-count:3}}dl{margin-bottom:2em}dl dl:last-child{margin-bottom:4em}dd{margin:0 0 1em 3em}#header-classes + dl > dd{margin-bottom:3em}dd dd{margin-left:2em}dd p{margin:10px 0}.name{background:#eee;font-weight:bold;font-size:.85em;padding:5px 10px;display:inline-block;min-width:40%}.name:hover{background:#e0e0e0}dt:target .name{background:var(--highlight-color)}.name > span:first-child{white-space:nowrap}.name.class > span:nth-child(2){margin-left:.4em}.inherited{color:#999;border-left:5px solid #eee;padding-left:1em}.inheritance em{font-style:normal;font-weight:bold}.desc h2{font-weight:400;font-size:1.25em}.desc h3{font-size:1em}.desc dt code{background:inherit}.source summary,.git-link-div{color:#666;text-align:right;font-weight:400;font-size:.8em;text-transform:uppercase}.source summary > *{white-space:nowrap;cursor:pointer}.git-link{color:inherit;margin-left:1em}.source pre{max-height:500px;overflow:auto;margin:0}.source pre code{font-size:12px;overflow:visible}.hlist{list-style:none}.hlist li{display:inline}.hlist li:after{content:',\2002'}.hlist li:last-child:after{content:none}.hlist .hlist{display:inline;padding-left:1em}img{max-width:100%}td{padding:0 .5em}.admonition{padding:.1em .5em;margin-bottom:1em}.admonition-title{font-weight:bold}.admonition.note,.admonition.info,.admonition.important{background:#aef}.admonition.todo,.admonition.versionadded,.admonition.tip,.admonition.hint{background:#dfd}.admonition.warning,.admonition.versionchanged,.admonition.deprecated{background:#fd4}.admonition.error,.admonition.danger,.admonition.caution{background:lightpink}</style>
13-
<style media="screen and (min-width: 700px)">@media screen and (min-width:700px){#sidebar{width:30%;height:100vh;overflow:auto;position:sticky;top:0}#content{width:70%;max-width:100ch;padding:3em 4em;border-left:1px solid #ddd}pre code{font-size:1em}.item .name{font-size:1em}main{display:flex;flex-direction:row-reverse;justify-content:flex-end}.toc ul ul,#index ul{padding-left:1.5em}.toc > ul > li{margin-top:.5em}}</style>
8+
<meta name="description" content="">
9+
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/10up-sanitize.css/13.0.0/sanitize.min.css" integrity="sha512-y1dtMcuvtTMJc1yPgEqF0ZjQbhnc/bFhyvIyVNb9Zk5mIGtqVaAB1Ttl28su8AvFMOY0EwRbAe+HCLqj6W7/KA==" crossorigin>
10+
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/10up-sanitize.css/13.0.0/typography.min.css" integrity="sha512-Y1DYSb995BAfxobCkKepB1BqJJTPrOp3zPL74AWFugHHmmdcvO+C48WLrUOlhGMc0QG7AE3f7gmvvcrmX2fDoA==" crossorigin>
11+
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/highlight.js/11.9.0/styles/default.min.css" crossorigin>
12+
<style>:root{--highlight-color:#fe9}.flex{display:flex !important}body{line-height:1.5em}#content{padding:20px}#sidebar{padding:1.5em;overflow:hidden}#sidebar > *:last-child{margin-bottom:2cm}.http-server-breadcrumbs{font-size:130%;margin:0 0 15px 0}#footer{font-size:.75em;padding:5px 30px;border-top:1px solid #ddd;text-align:right}#footer p{margin:0 0 0 1em;display:inline-block}#footer p:last-child{margin-right:30px}h1,h2,h3,h4,h5{font-weight:300}h1{font-size:2.5em;line-height:1.1em}h2{font-size:1.75em;margin:2em 0 .50em 0}h3{font-size:1.4em;margin:1.6em 0 .7em 0}h4{margin:0;font-size:105%}h1:target,h2:target,h3:target,h4:target,h5:target,h6:target{background:var(--highlight-color);padding:.2em 0}a{color:#058;text-decoration:none;transition:color .2s ease-in-out}a:visited{color:#503}a:hover{color:#b62}.title code{font-weight:bold}h2[id^="header-"]{margin-top:2em}.ident{color:#900;font-weight:bold}pre code{font-size:.8em;line-height:1.4em;padding:1em;display:block}code{background:#f3f3f3;font-family:"DejaVu Sans Mono",monospace;padding:1px 4px;overflow-wrap:break-word}h1 code{background:transparent}pre{border-top:1px solid #ccc;border-bottom:1px solid #ccc;margin:1em 0}#http-server-module-list{display:flex;flex-flow:column}#http-server-module-list div{display:flex}#http-server-module-list dt{min-width:10%}#http-server-module-list p{margin-top:0}.toc ul,#index{list-style-type:none;margin:0;padding:0}#index code{background:transparent}#index h3{border-bottom:1px solid #ddd}#index ul{padding:0}#index h4{margin-top:.6em;font-weight:bold}@media (min-width:200ex){#index .two-column{column-count:2}}@media (min-width:300ex){#index .two-column{column-count:3}}dl{margin-bottom:2em}dl dl:last-child{margin-bottom:4em}dd{margin:0 0 1em 3em}#header-classes + dl > dd{margin-bottom:3em}dd dd{margin-left:2em}dd p{margin:10px 0}.name{background:#eee;font-size:.85em;padding:5px 10px;display:inline-block;min-width:40%}.name:hover{background:#e0e0e0}dt:target .name{background:var(--highlight-color)}.name > span:first-child{white-space:nowrap}.name.class > span:nth-child(2){margin-left:.4em}.inherited{color:#999;border-left:5px solid #eee;padding-left:1em}.inheritance em{font-style:normal;font-weight:bold}.desc h2{font-weight:400;font-size:1.25em}.desc h3{font-size:1em}.desc dt code{background:inherit}.source > summary,.git-link-div{color:#666;text-align:right;font-weight:400;font-size:.8em;text-transform:uppercase}.source summary > *{white-space:nowrap;cursor:pointer}.git-link{color:inherit;margin-left:1em}.source pre{max-height:500px;overflow:auto;margin:0}.source pre code{font-size:12px;overflow:visible;min-width:max-content}.hlist{list-style:none}.hlist li{display:inline}.hlist li:after{content:',\2002'}.hlist li:last-child:after{content:none}.hlist .hlist{display:inline;padding-left:1em}img{max-width:100%}td{padding:0 .5em}.admonition{padding:.1em 1em;margin:1em 0}.admonition-title{font-weight:bold}.admonition.note,.admonition.info,.admonition.important{background:#aef}.admonition.todo,.admonition.versionadded,.admonition.tip,.admonition.hint{background:#dfd}.admonition.warning,.admonition.versionchanged,.admonition.deprecated{background:#fd4}.admonition.error,.admonition.danger,.admonition.caution{background:lightpink}</style>
13+
<style media="screen and (min-width: 700px)">@media screen and (min-width:700px){#sidebar{width:30%;height:100vh;overflow:auto;position:sticky;top:0}#content{width:70%;max-width:100ch;padding:3em 4em;border-left:1px solid #ddd}pre code{font-size:1em}.name{font-size:1em}main{display:flex;flex-direction:row-reverse;justify-content:flex-end}.toc ul ul,#index ul ul{padding-left:1em}.toc > ul > li{margin-top:.5em}}</style>
1414
<style media="print">@media print{#sidebar h1{page-break-before:always}.source{display:none}}@media print{*{background:transparent !important;color:#000 !important;box-shadow:none !important;text-shadow:none !important}a[href]:after{content:" (" attr(href) ")";font-size:90%}a[href][title]:after{content:none}abbr[title]:after{content:" (" attr(title) ")"}.ir a:after,a[href^="javascript:"]:after,a[href^="#"]:after{content:""}pre,blockquote{border:1px solid #999;page-break-inside:avoid}thead{display:table-header-group}tr,img{page-break-inside:avoid}img{max-width:100% !important}@page{margin:0.5cm}p,h2,h3{orphans:3;widows:3}h1,h2,h3,h4,h5,h6{page-break-after:avoid}}</style>
15-
<script defer src="https://cdnjs.cloudflare.com/ajax/libs/highlight.js/10.1.1/highlight.min.js" integrity="sha256-Uv3H6lx7dJmRfRvH8TH6kJD1TSK1aFcwgx+mdg3epi8=" crossorigin></script>
16-
<script>window.addEventListener('DOMContentLoaded', () => hljs.initHighlighting())</script>
15+
<script defer src="https://cdnjs.cloudflare.com/ajax/libs/highlight.js/11.9.0/highlight.min.js" integrity="sha512-D9gUyxqja7hBtkWpPWGt9wfbfaMGVt9gnyCvYa+jojwwPHLCzUm5i8rpk7vD7wNee9bA35eYIjobYPaQuKS1MQ==" crossorigin></script>
16+
<script>window.addEventListener('DOMContentLoaded', () => {
17+
hljs.configure({languages: ['bash', 'css', 'diff', 'graphql', 'ini', 'javascript', 'json', 'plaintext', 'python', 'python-repl', 'rust', 'shell', 'sql', 'typescript', 'xml', 'yaml']});
18+
hljs.highlightAll();
19+
/* Collapse source docstrings */
20+
setTimeout(() => {
21+
[...document.querySelectorAll('.hljs.language-python > .hljs-string')]
22+
.filter(el => el.innerHTML.length > 200 && ['"""', "'''"].includes(el.innerHTML.substring(0, 3)))
23+
.forEach(el => {
24+
let d = document.createElement('details');
25+
d.classList.add('hljs-string');
26+
d.innerHTML = '<summary>"""</summary>' + el.innerHTML.substring(3);
27+
el.replaceWith(d);
28+
});
29+
}, 100);
30+
})</script>
1731
</head>
1832
<body>
1933
<main>
@@ -22,49 +36,6 @@
2236
<h1 class="title">Module <code>pytm.report_util</code></h1>
2337
</header>
2438
<section id="section-intro">
25-
<details class="source">
26-
<summary>
27-
<span>Expand source code</span>
28-
</summary>
29-
<pre><code class="python">class ReportUtils:
30-
@staticmethod
31-
def getParentName(element):
32-
from pytm import Boundary
33-
if (isinstance(element, Boundary)):
34-
parent = element.inBoundary
35-
if (parent is not None):
36-
return parent.name
37-
else:
38-
return str(&#34;&#34;)
39-
else:
40-
return &#34;ERROR: getParentName method is not valid for &#34; + element.__class__.__name__
41-
42-
43-
@staticmethod
44-
def getNamesOfParents(element):
45-
from pytm import Boundary
46-
if (isinstance(element, Boundary)):
47-
parents = [p.name for p in element.parents()]
48-
return parents
49-
else:
50-
return &#34;ERROR: getNamesOfParents method is not valid for &#34; + element.__class__.__name__
51-
52-
@staticmethod
53-
def getFindingCount(element):
54-
from pytm import Element
55-
if (isinstance(element, Element)):
56-
return str(len(list(element.findings)))
57-
else:
58-
return &#34;ERROR: getFindingCount method is not valid for &#34; + element.__class__.__name__
59-
60-
@staticmethod
61-
def getElementType(element):
62-
from pytm import Element
63-
if (isinstance(element, Element)):
64-
return str(element.__class__.__name__)
65-
else:
66-
return &#34;ERROR: getElementType method is not valid for &#34; + element.__class__.__name__</code></pre>
67-
</details>
6839
</section>
6940
<section>
7041
</section>
@@ -79,7 +50,6 @@ <h2 class="section-title" id="header-classes">Classes</h2>
7950
<span>class <span class="ident">ReportUtils</span></span>
8051
</code></dt>
8152
<dd>
82-
<div class="desc"></div>
8353
<details class="source">
8454
<summary>
8555
<span>Expand source code</span>
@@ -123,13 +93,13 @@ <h2 class="section-title" id="header-classes">Classes</h2>
12393
else:
12494
return &#34;ERROR: getElementType method is not valid for &#34; + element.__class__.__name__</code></pre>
12595
</details>
96+
<div class="desc"></div>
12697
<h3>Static methods</h3>
12798
<dl>
12899
<dt id="pytm.report_util.ReportUtils.getElementType"><code class="name flex">
129100
<span>def <span class="ident">getElementType</span></span>(<span>element)</span>
130101
</code></dt>
131102
<dd>
132-
<div class="desc"></div>
133103
<details class="source">
134104
<summary>
135105
<span>Expand source code</span>
@@ -142,12 +112,12 @@ <h3>Static methods</h3>
142112
else:
143113
return &#34;ERROR: getElementType method is not valid for &#34; + element.__class__.__name__</code></pre>
144114
</details>
115+
<div class="desc"></div>
145116
</dd>
146117
<dt id="pytm.report_util.ReportUtils.getFindingCount"><code class="name flex">
147118
<span>def <span class="ident">getFindingCount</span></span>(<span>element)</span>
148119
</code></dt>
149120
<dd>
150-
<div class="desc"></div>
151121
<details class="source">
152122
<summary>
153123
<span>Expand source code</span>
@@ -160,12 +130,12 @@ <h3>Static methods</h3>
160130
else:
161131
return &#34;ERROR: getFindingCount method is not valid for &#34; + element.__class__.__name__</code></pre>
162132
</details>
133+
<div class="desc"></div>
163134
</dd>
164135
<dt id="pytm.report_util.ReportUtils.getNamesOfParents"><code class="name flex">
165136
<span>def <span class="ident">getNamesOfParents</span></span>(<span>element)</span>
166137
</code></dt>
167138
<dd>
168-
<div class="desc"></div>
169139
<details class="source">
170140
<summary>
171141
<span>Expand source code</span>
@@ -179,12 +149,12 @@ <h3>Static methods</h3>
179149
else:
180150
return &#34;ERROR: getNamesOfParents method is not valid for &#34; + element.__class__.__name__</code></pre>
181151
</details>
152+
<div class="desc"></div>
182153
</dd>
183154
<dt id="pytm.report_util.ReportUtils.getParentName"><code class="name flex">
184155
<span>def <span class="ident">getParentName</span></span>(<span>element)</span>
185156
</code></dt>
186157
<dd>
187-
<div class="desc"></div>
188158
<details class="source">
189159
<summary>
190160
<span>Expand source code</span>
@@ -201,14 +171,14 @@ <h3>Static methods</h3>
201171
else:
202172
return &#34;ERROR: getParentName method is not valid for &#34; + element.__class__.__name__</code></pre>
203173
</details>
174+
<div class="desc"></div>
204175
</dd>
205176
</dl>
206177
</dd>
207178
</dl>
208179
</section>
209180
</article>
210181
<nav id="sidebar">
211-
<h1>Index</h1>
212182
<div class="toc">
213183
<ul></ul>
214184
</div>
@@ -235,7 +205,7 @@ <h4><code><a title="pytm.report_util.ReportUtils" href="#pytm.report_util.Report
235205
</nav>
236206
</main>
237207
<footer id="footer">
238-
<p>Generated by <a href="https://pdoc3.github.io/pdoc" title="pdoc: Python API documentation generator"><cite>pdoc</cite> 0.10.0</a>.</p>
208+
<p>Generated by <a href="https://pdoc3.github.io/pdoc" title="pdoc: Python API documentation generator"><cite>pdoc</cite> 0.11.6</a>.</p>
239209
</footer>
240210
</body>
241-
</html>
211+
</html>

docs/threats.md

Lines changed: 52 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2677,3 +2677,55 @@ If no mechanism is in place for managing credentials (passwords and certificates
26772677

26782678

26792679

2680+
## AC23 Credentials Disclosure
2681+
2682+
If credentials (passwords or certificates) have a long lifetime their disclosure can have severe consequences, if the credentials cannot quickly be revoked and/or rotated.
2683+
2684+
<dl>
2685+
<dt>Severity</dt>
2686+
<dd>High</dd>
2687+
2688+
<dt>Prerequisites</dt>
2689+
<dd></dd>
2690+
2691+
<dt>Example</dt>
2692+
<dd></dd>
2693+
2694+
<dt>Mitigations</dt>
2695+
<dd>Long living credentials need to have high entropy and length to be future proof, especially if it is unknwon how long these credentials will be used. Further should there be a mechanism to revoke the credentials immediately if a disclosure is suspected. To detect disclosure of the credentials their use should be monitored for suspicions activity.</dd>
2696+
2697+
<dt>References</dt>
2698+
<dd>https://pages.nist.gov/800-63-3/sp800-63b.html#sec6</dd>
2699+
2700+
<dt>Condition</dt>
2701+
<dd>any(d.isCredentials for d in target.data) and target.sink.inScope and any(d.credentialsLife in (Lifetime.UNKNOWN, Lifetime.LONG, Lifetime.MANUAL) for d in target.data)</dd>
2702+
</dl>
2703+
2704+
2705+
2706+
## AC24 Use of hardcoded credentials
2707+
2708+
Hardcoded credentials (password or certificates) cannot be changed and if these credentials are dislcosed they can be used by attackers to bypass the authentication mechanism.
2709+
2710+
<dl>
2711+
<dt>Severity</dt>
2712+
<dd>Very High</dd>
2713+
2714+
<dt>Prerequisites</dt>
2715+
<dd></dd>
2716+
2717+
<dt>Example</dt>
2718+
<dd></dd>
2719+
2720+
<dt>Mitigations</dt>
2721+
<dd>Avoid hardcoded credentials. If you have to use hardcoded credentials make is possible to change the credentials or to deactivate them. A typical design is to use a "first login"-mode which forces the user to create new credentials, on the first login. If the credentials cannot be changed the sole actions in prodcution for the defender is to deactivate/remove the effected product.</dd>
2722+
2723+
<dt>References</dt>
2724+
<dd>https://cwe.mitre.org/data/definitions/798.html, https://cwe.mitre.org/data/definitions/259.html, https://cwe.mitre.org/data/definitions/321.html</dd>
2725+
2726+
<dt>Condition</dt>
2727+
<dd>any(d.isCredentials for d in target.data) and target.sink.inScope and any(d.credentialsLife == Lifetime.HARDCODED for d in target.data)</dd>
2728+
</dl>
2729+
2730+
2731+

requirements.txt

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +0,0 @@
1-
pydal>=20200714.1

setup.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,7 @@
2525
"Natural Language :: English",
2626
],
2727
python_requires=">=3",
28-
install_requires=["pydal>=20200714.1"],
28+
install_requires=[],
2929
package_data={
3030
"pytm": [
3131
"images/datastore.png",

0 commit comments

Comments
 (0)