Skip to content

Commit 94d5e23

Browse files
authored
Merge pull request #7 from Chave0v0/dev
v2.0.0 完成敏感信息检查功能
2 parents 6d7d93d + 4278de0 commit 94d5e23

32 files changed

+1663
-588
lines changed

.idea/API-Highlighter.iml

Lines changed: 1 addition & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

.idea/libraries/Maven__org_yaml_snakeyaml_2_0.xml

Lines changed: 13 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

README.md

Lines changed: 70 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -185,8 +185,75 @@ Java 版本不仅更好地与 BurpSuite 环境集成,而且通过减少第三
185185

186186
![image-20250131204256345](assets/image-20250131204256345.png)
187187

188+
### 敏感信息检查
189+
190+
目前采用 HaE 部分敏感信息规则进行检查。
191+
192+
首次安装插件时,会在当前用户目录下创建配置文件夹。
193+
194+
![image-20250203170903647](assets/image-20250203170903647.png)
195+
196+
#### 开启功能
197+
198+
开启敏感信息检查功能必须先导入 API,该功能仅对 API 列表中匹配的记录进行检查。
199+
200+
![image-20250203214020393](assets/image-20250203214020393.png)
201+
202+
导入 API 后,在 `Sensitive Info` 标签页勾选开启敏感信息检查。该勾选状态默认不勾选,状态不保存。
203+
204+
初次启用功能由于配置文件不存在,会询问是否使用默认规则,选择是即可自动创建规则文件。
205+
206+
![image-20250203214446338](assets/image-20250203214446338.png)
207+
208+
插件自带规则均来自 HaE 插件部分敏感信息规则。
209+
210+
![image-20250203214514020](assets/image-20250203214514020.png)
211+
212+
#### 编辑规则
213+
214+
所有修改均同步本地配置文件。
215+
216+
##### 添加规则
217+
218+
![image-20250203230445654](assets/image-20250203230445654.png)
219+
220+
![image-20250203230544618](assets/image-20250203230544618.png)
221+
222+
##### 修改规则
223+
224+
![image-20250203230640616](assets/image-20250203230640616.png)
225+
226+
![image-20250203230657728](assets/image-20250203230657728.png)
227+
228+
![image-20250203230720331](assets/image-20250203230720331.png)
229+
230+
##### 删除规则
231+
232+
支持选中多条规则同时删除。
233+
234+
![image-20250203231321030](assets/image-20250203231321030.png)
235+
236+
![image-20250203231338677](assets/image-20250203231338677.png)
237+
238+
##### 切换规则启用状态
239+
240+
支持选中多条规则同时切换状态,`true=启用``false=未启用`
241+
242+
![image-20250203231607512](assets/image-20250203231607512.png)
243+
244+
![image-20250203231625954](assets/image-20250203231625954.png)
245+
246+
#### 功能效果
247+
248+
开启敏感信息检查后,当 API 列表中匹配到敏感信息时,`history` 中标记为 `红色`,同时列出匹配到的字段信息。
249+
250+
![image-20250203232046025](assets/image-20250203232046025.png)
251+
252+
同时 API 列表中 `Result` 字段提示 `存在敏感信息`
253+
254+
![image-20250203232232994](assets/image-20250203232232994.png)
255+
188256
## 更新计划
189257

190-
- HaE 规则敏感信息检查
191-
- API 未授权访问检查
192-
- 列表排序
258+
- HaE 规则敏感信息检查(v2.0.0 已完成)
259+
- API 未授权访问检查(v3.0.0 开发中)

assets/image-20250203170903647.png

98.5 KB
Loading

assets/image-20250203214020393.png

36.5 KB
Loading

assets/image-20250203214446338.png

176 KB
Loading

assets/image-20250203214514020.png

166 KB
Loading

assets/image-20250203230445654.png

289 KB
Loading

assets/image-20250203230544618.png

169 KB
Loading

assets/image-20250203230640616.png

170 KB
Loading

0 commit comments

Comments
 (0)