Find sensitive API endpoints
Recipe ID
org.openrewrite.java.security.search.FindSensitiveApiEndpointsArtifact
org.openrewrite.recipe:rewrite-java-securityFind data models exposed by REST APIs that contain sensitive information like PII and secrets.
Usage
You’ll need the Moderne CLI configured before running the command below.
mod run . --recipe org.openrewrite.java.security.search.FindSensitiveApiEndpoints --recipe-option "fieldNames=password,dateOfBirth,dob,ssn"If the recipe isn’t available locally, install it with:
mod config recipes jar install org.openrewrite.recipe:rewrite-java-security:3.36.0Options
| Name | Type | Description |
|---|---|---|
fieldNamesrequired | List | Field names to search for. e.g. password,dateOfBirth,dob,ssn |
transitive | Boolean | Find model objects that contain other model objects that contain sensitive data. |
Data tables
Structured output this recipe can produce.
- Sensitive API endpointsThe API endpoints that expose sensitive data.
org.openrewrite.java.security.table.SensitiveApiEndpoints - Source files that had resultsSource files that were modified by the recipe run.
org.openrewrite.table.SourcesFileResults - Source files that had search resultsSearch results that were found during the recipe run.
org.openrewrite.table.SearchResults - Source files that errored on a recipeThe details of all errors produced by a recipe run.
org.openrewrite.table.SourcesFileErrors - Recipe performanceStatistics used in analyzing the performance of recipes.
org.openrewrite.table.RecipeRunStats