#!/usr/bin/env bash # Check important deployed security headers and PHP session cookie flags. set -u fail=0 check_contains() { local name="$1" local haystack="$2" local needle="$3" if printf '%s' "$haystack" | grep -Fqi "$needle"; then printf 'OK: %s\n' "$name" else printf 'FAIL: %s missing %s\n' "$name" "$needle" >&2 fail=1 fi } check_not_contains() { local name="$1" local haystack="$2" local needle="$3" if printf '%s' "$haystack" | grep -Fqi "$needle"; then printf 'FAIL: %s contains %s\n' "$name" "$needle" >&2 fail=1 else printf 'OK: %s\n' "$name" fi } fetch_headers() { local host="$1" local path="$2" curl -skI --resolve "${host}:443:127.0.0.1" "https://${host}${path}" } www_headers="$(fetch_headers www.sillylaird.ca /)" # Session cookies are only set on pages that start a session (admin login, admin panel). admin_headers="$(fetch_headers www.sillylaird.ca /admin/login.php)" guestbook_headers="$(fetch_headers guestbook.sillylaird.ca /form.php)" check_contains "www cookie Secure" "$admin_headers" "set-cookie: PHPSESSID=" check_contains "www cookie Secure" "$admin_headers" "secure" check_contains "www cookie HttpOnly" "$admin_headers" "httponly" check_contains "www cookie SameSite" "$admin_headers" "samesite=lax" check_contains "www HSTS" "$www_headers" "strict-transport-security:" check_contains "www nosniff" "$www_headers" "x-content-type-options: nosniff" check_contains "www CSP" "$www_headers" "content-security-policy:" check_contains "www CSP frame policy" "$www_headers" "frame-ancestors 'none'" check_not_contains "www server version" "$www_headers" "nginx/" check_contains "guestbook cookie Secure" "$guestbook_headers" "set-cookie: PHPSESSID=" check_contains "guestbook cookie Secure" "$guestbook_headers" "secure" check_contains "guestbook cookie HttpOnly" "$guestbook_headers" "httponly" check_contains "guestbook cookie SameSite" "$guestbook_headers" "samesite=lax" check_contains "guestbook HSTS" "$guestbook_headers" "strict-transport-security:" check_contains "guestbook nosniff" "$guestbook_headers" "x-content-type-options: nosniff" check_contains "guestbook CSP frame policy" "$guestbook_headers" "frame-ancestors https://www.sillylaird.ca" check_not_contains "guestbook server version" "$guestbook_headers" "nginx/" exit "$fail"