Ajax スパイダー – 自動化フレームワーク対応

このアドオンは自動化フレームワークに対応しています。

ジョブ: spiderAjax

spiderAjaxジョブにより、AJAXスパイダーを実行できます。これは従来のスパイダーよりも低速ですが、最新のWebアプリケーションをうまく処理します。

この内容は、動画「ZAP Chat 10 Automation Framework Part 4 - Spidering」で解説されています。

このジョブはモニターテストをサポートしています。

  - type: spiderAjax                   # The ajax spider - slower than the spider but handles modern apps well
    parameters:
      context:                         # String: Name of the context to spider, default: first context
      user:                            # String: An optional user to use for authentication, must be defined in the env
      url:                             # String: Url to start spidering from, default: first context URL
      maxDuration:                     # Int: The max time in minutes the ajax spider will be allowed to run for, default: 0 unlimited
      maxCrawlDepth:                   # Int: The max depth that the crawler can reach, default: 10, 0 is unlimited
      numberOfBrowsers:                # Int: The number of browsers the spider will use, more will be faster but will use up more memory, default: number of cores
      runOnlyIfModern:                 # Boolean: If true then the spider will only run if a "modern app" alert is raised, default: false
      inScopeOnly:                     # Boolean: If true then any URLs requested which are out of scope will be ignored, default: true
      enableExtensions:                # Bool: When enabled then will use any browser extensions added by other add-ons, default: false
      browserId:                       # String: Browser Id to use, default: firefox-headless
      clickDefaultElems:               # Bool: When enabled only click the default element: 'a', 'button' and 'input', default: true
      clickElemsOnce:                  # Bool: When enabled only click each element once, default: true
      eventWait:                       # Int: The time in milliseconds to wait after a client side event is fired, default: 1000
      maxCrawlStates:                  # Int: The maximum number of crawl states the crawler should crawl, default: 0 unlimited
      randomInputs:                    # Bool: When enabled random values will be entered into input element, default: true
      reloadWait:                      # Int: The time in milliseconds to wait after the URL is loaded, default: 1000
      scopeCheck:                      # String: The scope check, either Flexible or Strict, default: Strict
      logoutAvoidance:                 # Bool: When enabled, the spider will avoid clicking common logout elements, default: false
      elements:                        # A list of HTML elements to click - will be ignored unless clickDefaultElems is false
      - "a"
      - "button"
      - "input"
      excludedElements:                 # A list of HTML elements to exclude from click.
        - description: "Logout Button"  # 文字列: 除外の説明
          element: "button"             # 文字列: 要素の名前
          xpath:                        # 文字列: 要素のXPath、オプション
          text:                         # 文字列: 要素のテキスト (完全一致、大文字と小文字を区別)、オプション
          attributeName: "aria-label"   # 文字列: 属性の名前、値が提供されていない限りオプション
          attributeValue: "Logout"      # 文字列: 属性の値、名前が提供されていない限りオプション
      
    tests:
      - name: 'At least 100 URLs found'      # 文字列: テストの名前、デフォルト: statistic + operator + value
        type: 'stats'                        # 文字列: テストのタイプ、現在は'stats'のみサポート
        statistic: 'stats.spiderAjax.urls.added'   # 文字列: 整数/long統計の名前、現在サポート: 'stats.spiderAjax.urls.added'
        operator: '>='                       # 文字列['==', '!=', '>=', '>', '<', '<=']: テストに使用する演算子
        value: 100                           # Int: 見つかると予想されるURLの数に変更する
        onFail: 'info'                       # 文字列[warn, error, info]: テストを有効にするには、これを 'warn' または 'error' に変更してください
runOnlyIfModern が True に設定されている場合、passiveScan-waitジョブをこのジョブの前 (および後) に実行する必要があり、またモダンWebアプリケーションルールがインストールされ、有効になっている必要があります。 これらのいずれかが行われていない場合、AJAXスパイダーは常に実行され、警告が出力されます。 両方が行われており、"モダンWebアプリケーション"のアラートが発生しない場合、これは従来のアプリケーションであり、AJAXスパイダーは不要であると判断されます。 以前は、統計情報 "spiderAjax.urls.started" が提供されていました。 これは非推奨であり、将来のいずれかの時点で削除される予定です。