Zest

Zest is an experimental specialized scripting language (also known as a domain-specific language) originally developed by the Mozilla security team and is intended to be used in web oriented security tools.

Il est inclus par défaut avec ZAP.

Engine Name

The engine is named Mozilla Zest, which should be used when manually/programmatically configuring ZAP.

La création de Zeste de scripts

Il existe une variété de façons de créer Zeste de scripts:

Enregistrer un nouvel élan Bouton script

Le nouveau Zeste de script sera affiché dans l'onglet Scripts avec un rouge "enregistrement" de l'icône.
Toutes les demandes que vous faites sous le préfixe spécifié sera ajouté dans le script.
Appuyez sur le "Enregistrement d'un nouveau Zeste de script" à nouveau pour arrêter l'enregistrement de la demande.
Notez que vous pouvez seulement enregistrer 'Autonome' Zeste de scripts de cette façon. Si vous souhaitez créer d'autres types de Zeste de script, vous devez utiliser un autre mécanisme.

Vous pouvez également faire un clic droit n'importe Autonome Zeste de script et utiliser le "Démarrer l'enregistrement" et "Arrêter l'enregistrement" des boutons.

There are two primary methods for script recording: server-side and client-side. For client-side recording, we leverage the ZAP browser extension and a dedicated client add-on.
This combination allows us to efficiently capture and save user interactions in Zest scripts.

New Script Button

Any type of Zest script can be created this way.

Right clicking a Zest template

Any type of Zest script can be created this way.

Right clicking requests

Note that you can only add request to 'Stand Alone' Zest scripts.

Plug-n-Hack

If you are using a recent version of Firefox then you can create Zest scripts from within your browser.
Note that you can only record 'Stand Alone' Zest scripts in this way. If you want to create other types of Zest script you must use another mechanism.

Editing Zest scripts

Zest scripts are edited graphically in the Scripts tree tab.
Each statement is a node in the tree - double click nodes to edit the statement properties.
You can add, move and remove statements via right clicking the Zest nodes.
You can also add requests to 'Stand alone' Zest scripts by right clicking the requests in any of the other tabs.
There are also some right click options available when you select text in the Request or Response tabs.

Zest includes a set of 'built in' variables as well as allowing you to declare your own.
A right click menu is provided (where relevant) in the edit dialogs to allow you to paste in any of the available variable names.

Authentication Scripts

Authentication scripts can use a custom ZAP variable, called TOTP, to send a value to an input field with a TOTP code generated from the user's credentials TOTP data.

Import/Export Integration

When the Import/Export add-on is installed, Zest adds the following functionality:

Import Zest Script

An option to import messages from a Zest script file is available via the 'Import' menu ('Import Zest Script...'). The HTTP requests (and responses, if present) from the script are added to the Sites tree and History panel without replaying them.

Export as Zest Script

The Export menu supports exporting the history as a Zest script file. This creates a Zest script containing the HTTP requests (and responses).

Automation Framework

When both the Import/Export and Automation add-ons are installed, Zest scripts can be imported and exported via the Automation Framework.

Import Job

Use the Import/Export add-on's import job with type: zest to import HTTP messages from a Zest script file (.zst):
  - type: import
    parameters:
      type: zest
      fileName: /path/to/script.zst
The HTTP requests (and responses, if present) from the script are added to the Sites tree and History panel without replaying them.

Export Job

Use the Import/Export add-on's export job with type: zest to export messages to a Zest script file. The source parameter can be history (manually/proxied messages) or all (all messages including those generated by ZAP):
  - type: export
    parameters:
      type: zest
      source: history
      fileName: /path/to/output.zst

External links

     https://github.com/zaproxy/zest/ The Zest GitHub repository, including details of the language