Retain recorded eligibility evidence scope in HTML reports

This commit is contained in:
Shirofune-Security committed 2026-09-19 07:25:44 +09:00
1 parent 36ad97114c
commit d6da8f82c8
2 files changed
+18 -2

No files matched your search

+8 -2
View File
@@ -386,8 +386,14 @@ function Export-WelaRuleEligibility {
$encode = { param($value) [Net.WebUtility]::HtmlEncode([string]$value) }
$html = New-Object Text.StringBuilder
[void]$html.Append('<!doctype html><html lang="en"><meta charset="utf-8"><title>WELA native rule eligibility</title><style>body{font:16px sans-serif;margin:2rem}table{border-collapse:collapse;width:100%}td,th{border-bottom:1px solid #ccc;padding:.5rem;text-align:left}code{overflow-wrap:anywhere}</style><h1>Native rule eligibility</h1>')
[void]$html.Append('<p>' + (& $encode $Report.AssessmentBasis) + '</p><pre>' + (& $encode ($Report.Summary | ConvertTo-Json -Depth 6)) + '</pre><p>Corpus SHA256: <code>' + (& $encode $Report.Corpus.Sha256) + '</code></p><table><tr><th>Rule</th><th>State</th><th>Reasons</th></tr>')
foreach ($row in $Report.Results) { [void]$html.Append('<tr><td>' + (& $encode ($row.Title + ' [' + $row.Id + ']')) + '</td><td>' + (& $encode $row.State) + '</td><td>' + (& $encode ((@($row.Reasons) + @($row.ScopeExclusion)) -join '; ')) + '</td></tr>') }
[void]$html.Append('<p>' + (& $encode $Report.AssessmentBasis) + '</p><pre>' + (& $encode ($Report.Summary | ConvertTo-Json -Depth 6)) + '</pre><h2>Requested context</h2><pre>' + (& $encode ($Report.RequestedContext | ConvertTo-Json -Depth 6)) + '</pre><p>Corpus SHA256: <code>' + (& $encode $Report.Corpus.Sha256) + '</code></p><table><tr><th>Rule</th><th>State</th><th>Reasons and recorded evidence scope</th></tr>')
foreach ($row in $Report.Results) {
[void]$html.Append('<tr><td>' + (& $encode ($row.Title + ' [' + $row.Id + ']')) + '</td><td>' + (& $encode $row.State) + '</td><td>' + (& $encode ((@($row.Reasons) + @($row.ScopeExclusion)) -join '; ')))
if ($row.State -eq 'Ready') {
[void]$html.Append('<p>Evidence as of UTC: <code>' + (& $encode $row.EvidenceAsOfUtc) + '</code></p><p>Recorded context (not the current host):</p><pre>' + (& $encode ($row.EvidenceContext | ConvertTo-Json -Depth 6)) + '</pre>')
}
[void]$html.Append('</td></tr>')
}
[void]$html.Append('</table></html>')
$html.ToString() | Set-Content -LiteralPath $HtmlPath -Encoding UTF8 -ErrorAction Stop
}
+10
View File
@@ -87,6 +87,16 @@ try {
Reset-Evidence;$r=Report -Evidence
Assert ($r.Summary.Ready -eq 1 -and $r.Results[0].State -eq 'Ready') ('Coherent complete synthetic evidence demonstrates the importer gates: '+($r.Results[0].Reasons -join '; '))
Assert ($r.Results[0].EvidenceContext.computer -eq 'lab.example.test' -and $r.AssessmentBasis -like '*not a current-host*') 'Imported Ready states retain their recorded host/time and explicit limitations.'
$evidenceHtml=Join-Path $root 'evidence.html'
Export-WelaRuleEligibility -Report $r -HtmlPath $evidenceHtml
$exported=[IO.File]::ReadAllText($evidenceHtml)
foreach ($required in @('Requested context','lab.example.test','Client','26100','fixture-1','domainJoined','installedRoles','fixture-backend','backendVersion','2026-09-19T10:04:00Z')) {
Assert ($exported.Contains($required)) "Shared HTML must retain evidence scope: $required"
}
$r.Results[0].EvidenceContext.computer='<script>alert("fixture")</script>'
Export-WelaRuleEligibility -Report $r -HtmlPath $evidenceHtml
$exported=[IO.File]::ReadAllText($evidenceHtml)
Assert (-not $exported.Contains('<script>') -and $exported.Contains('&lt;script&gt;')) 'Evidence context is HTML-encoded rather than executable markup.'
foreach ($name in @('sourceRule','normalizedRule','review','beforeState','afterState','eventXml','ingestion','query','queryResult')) {
Reset-Evidence;$script:record.artifacts.Remove($name);Assert-NotReady "Missing $name prevents Ready."
}