"""Kleiner Testserver fuer den lokalen Passivitaetsbeweis der ZAP-Grundpruefung. Aufruf: python3 -I zap-testserver.py PORT LOGDATEI [require-auth] / verweist auf /login und /info, /login enthaelt ein POST-Formular mit Benutzer, Passwort und Absende-Knopf. Jede Anfrage wird als "METHODE PFAD auth=ja|nein" protokolliert. Mit require-auth beantwortet der Server jede Anfrage ohne Authorization-Kopf mit 401. Nur Testwerte, keine echten Zugangsdaten. """ import sys from http.server import BaseHTTPRequestHandler, HTTPServer PORT = int(sys.argv[1]) LOG = sys.argv[2] REQUIRE_AUTH = len(sys.argv) > 3 and sys.argv[3] == "require-auth" PAGES = { "/": 'Anmelden Info', "/login": ( '
' '' '
' ), "/info": '

Info

zurueck', } class Handler(BaseHTTPRequestHandler): def _log(self): auth = "ja" if self.headers.get("Authorization") else "nein" with open(LOG, "a", encoding="utf-8") as fh: fh.write("%s %s auth=%s\n" % (self.command, self.path, auth)) return auth == "ja" def _answer(self): has_auth = self._log() if REQUIRE_AUTH and not has_auth: self.send_response(401) self.send_header("WWW-Authenticate", 'Basic realm="test"') self.send_header("Content-Length", "0") self.end_headers() return body = PAGES.get(self.path.split("?")[0], "nicht gefunden") code = 200 if self.path.split("?")[0] in PAGES else 404 data = body.encode("utf-8") self.send_response(code) self.send_header("Content-Type", "text/html; charset=utf-8") self.send_header("Content-Length", str(len(data))) self.end_headers() if self.command != "HEAD": self.wfile.write(data) do_GET = do_POST = do_HEAD = do_PUT = do_DELETE = do_OPTIONS = _answer def log_message(self, *args): pass HTTPServer(("0.0.0.0", PORT), Handler).serve_forever()