aboutsummaryrefslogtreecommitdiffstats
path: root/tools/security_check.sh
diff options
context:
space:
mode:
Diffstat (limited to '')
-rwxr-xr-xtools/security_check.sh62
1 files changed, 62 insertions, 0 deletions
diff --git a/tools/security_check.sh b/tools/security_check.sh
new file mode 100755
index 0000000..e62fa57
--- /dev/null
+++ b/tools/security_check.sh
@@ -0,0 +1,62 @@
+#!/usr/bin/env bash
+# Check important deployed security headers and PHP session cookie flags.
+
+set -u
+
+fail=0
+
+check_contains() {
+ local name="$1"
+ local haystack="$2"
+ local needle="$3"
+ if printf '%s' "$haystack" | grep -Fqi "$needle"; then
+ printf 'OK: %s\n' "$name"
+ else
+ printf 'FAIL: %s missing %s\n' "$name" "$needle" >&2
+ fail=1
+ fi
+}
+
+check_not_contains() {
+ local name="$1"
+ local haystack="$2"
+ local needle="$3"
+ if printf '%s' "$haystack" | grep -Fqi "$needle"; then
+ printf 'FAIL: %s contains %s\n' "$name" "$needle" >&2
+ fail=1
+ else
+ printf 'OK: %s\n' "$name"
+ fi
+}
+
+fetch_headers() {
+ local host="$1"
+ local path="$2"
+ curl -skI --resolve "${host}:443:127.0.0.1" "https://${host}${path}"
+}
+
+www_headers="$(fetch_headers www.sillylaird.ca /)"
+# Session cookies are only set on pages that start a session (admin login, admin panel).
+admin_headers="$(fetch_headers www.sillylaird.ca /admin/login.php)"
+guestbook_headers="$(fetch_headers guestbook.sillylaird.ca /form.php)"
+
+check_contains "www cookie Secure" "$admin_headers" "set-cookie: PHPSESSID="
+check_contains "www cookie Secure" "$admin_headers" "secure"
+check_contains "www cookie HttpOnly" "$admin_headers" "httponly"
+check_contains "www cookie SameSite" "$admin_headers" "samesite=lax"
+check_contains "www HSTS" "$www_headers" "strict-transport-security:"
+check_contains "www nosniff" "$www_headers" "x-content-type-options: nosniff"
+check_contains "www CSP" "$www_headers" "content-security-policy:"
+check_contains "www CSP frame policy" "$www_headers" "frame-ancestors 'none'"
+check_not_contains "www server version" "$www_headers" "nginx/"
+
+check_contains "guestbook cookie Secure" "$guestbook_headers" "set-cookie: PHPSESSID="
+check_contains "guestbook cookie Secure" "$guestbook_headers" "secure"
+check_contains "guestbook cookie HttpOnly" "$guestbook_headers" "httponly"
+check_contains "guestbook cookie SameSite" "$guestbook_headers" "samesite=lax"
+check_contains "guestbook HSTS" "$guestbook_headers" "strict-transport-security:"
+check_contains "guestbook nosniff" "$guestbook_headers" "x-content-type-options: nosniff"
+check_contains "guestbook CSP frame policy" "$guestbook_headers" "frame-ancestors https://www.sillylaird.ca"
+check_not_contains "guestbook server version" "$guestbook_headers" "nginx/"
+
+exit "$fail"