We know how frustrating the authentication process in DAST scans can be, which is why we've made several key updates to streamline it! Our goal is to provide you with better flexibility and efficiency for your security testing needs.
Here's the full list:
We now support more complex authentication processes through the new Browser Actions Authentication Preset. This is especially useful for scenarios where traditional authentication methods don’t work well. With Browser Actions, you can customize your authentication flow using browser actions rather than relying on Escape's AI agent. This is ideal for form-based authentication where inputs are provided directly by users.
The Browser Actions preset uses Playwright for browser automation actions, such as filling in forms and clicking buttons. By default, it extracts cookies, localStorage, and sessionStorage from the browser, injecting them into the scan engine for frontend scans. For API scans, only cookies are injected.
Key benefits:
- Customize authentication flows using direct browser actions.
- Automatically extract and inject cookies and storage (for frontend scans).
- Configure extractions and injections for specific storage needs (e.g., local/session storage).
For detailed documentation and some examples of how you can set it up, visit: Browser Actions Authentication Preset.
We’ve introduced a new Single Page Mode to handle use cases where enterprise applications allow only one user to be logged in at a time. This feature ensures that authentication is managed seamlessly in environments with strict session controls, eliminating the need for additional configurations or manual intervention. Once authenticated, the system will maintain that connection throughout the scan.
For applications that automatically log users out when the tab is closed, our system now ensures that reauthentication is handled automatically. There's no need to reconfigure your DAST scan setup or manually log in again—everything is managed in the background, allowing for a smooth and uninterrupted scanning process.
In cases where applications do not allow multiple tabs to be logged in simultaneously, our updated DAST scanning process automatically manages reauthentication. This removes the hassle of managing tab states and ensures that your scan continues without the need to manually re-authenticate across multiple tabs.
The improvements we've made to our DAST scanning authentication process addressed the specific pain points our customers face, especially for complex or custom authentication systems! With these updates, you can now handle advanced authentication workflows, such as the one described above, without losing session continuity or compromising on scan effectiveness!