Skip to content

Narrow WebApp.API server detection false positives - #660

Closed
Giulia Stocco (gfs) with Copilot wants to merge 8 commits into
mainfrom
copilot/update-pr-651-resolve-issues
Closed

Giulia Stocco (gfs) with Copilot wants to merge 8 commits into
mainfrom
copilot/update-pr-651-resolve-issues

Conversation

Copilot AI commented Sep 10, 2026 •

Copy link
Copy Markdown
Contributor

Addresses remaining review feedback where client-only or non-HTTP framework usage could be classified as exposed APIs. Tightens server signals while preserving real API detections and Kotlin source resolution.

  • Rule precision

    • DRF: replaces generic rest_framework import matching with API view/viewset/router signals.
    • NestJS: removes @nestjs/common import matching; uses controller decorators.
    • Spring: gates mapping annotations on controller context to avoid OpenFeign clients.
    • JAX-RS: detects resource/application classes or server registration instead of annotation imports.
  • Regression coverage

    • Adds positives and negatives for serializer-only DRF, Injectable-only NestJS, OpenFeign clients, declarative/programmatic JAX-RS clients, and mixed client/server files.
    • Adds language resolution coverage for .kt while preserving .kts.
  • Buildability

    • Repairs a PR-head RuleProcessor merge artifact so sync/async analysis continues through the shared capture-filtering path.

Example behavior:

@RegisterRestClient
@Path("/remote")
interface RemoteClient {
    @GET String get(); // no WebApp.API finding
}

@Path("/local")
public class LocalResource {
    @GET public String get() { return "ok"; } // WebApp.API.Java.JaxRs
}

Giulia Stocco (gfs) and others added 5 commits August 1, 2026 11:47
Allow explicitly targeted rules to report build-file findings while preserving suppression for universal rules.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: f0f9dbe0-e8ba-472b-b645-eda10038e683
Adds 34 rules under WebApp.API.* that identify when a repository exposes
an HTTP, gRPC, or GraphQL API, covering Python, JavaScript/TypeScript,
.NET, JVM, Go, Ruby, PHP, Rust, and OpenAPI/Swagger documents.

Six rules whose patterns are inherently low precision (framework-agnostic
route registration such as `@x.get(`, `app.get(`, `.MapGet(`) are gated
behind a rule-level `same-file` condition requiring a matching framework
import, so they only fire in files that actually use the framework.

Also:
- Adds an "Exposed web API" entry to the HTML report's Select Features
  group so WebApp.API findings are surfaced in generated reports.
- Adds `.kt` to the kotlin entry in languages.json. Only `.kts` was
  listed, so ordinary Kotlin source files were never scanned.

Builds on the parent commit, which stopped RuleProcessor from suppressing
tags emitted by rules that explicitly target build-type files. Two rules
here depend on that: AI090202 reads Azure Functions bindings from
function.json, and AI090800 reads OpenAPI documents from json and yaml.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: cac8997c-55eb-4b89-aebd-6592d0525759
Co-authored-by: gfs <98900+gfs@users.noreply.github.com>
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

Copilot AI and others added 3 commits September 10, 2026 22:51
Co-authored-by: gfs <98900+gfs@users.noreply.github.com>
Co-authored-by: gfs <98900+gfs@users.noreply.github.com>
…sues' into copilot/update-pr-651-resolve-issues

Co-authored-by: gfs <98900+gfs@users.noreply.github.com>
Copilot AI changed the title [WIP] Resolve issues from code review for PR #651 Narrow WebApp.API server detection false positives Sep 10, 2026
@gfs
Giulia Stocco (gfs) deleted the copilot/update-pr-651-resolve-issues branch September 14, 2026 19:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants