Business Logic Recorder
The Business Logic Recorder allows you to browse and record navigation within your web application or target, enabling FortiDAST to discover additional navigation paths, URIs, cookies, and APIs for enhanced scan coverage.
|
|
|
Creating a new recording
You can create up to 10 recordings. To record a business logic sequence:
-
Navigate to Scans Policy > Scan Configuration page. See Configuring the Scanner.
-
In the Replay with Automation section, select Business Logic Recorder tab.
-
Configure a session timeout from one to 24 hours.
-
Click New Recording. The target URL launches in Business Logic Recorder window.
-
Perform the necessary navigation and actions within the web application and click Save. You cannot use the tab key within the embedded browser. If the back button is clicked multiple times, a blank page may display. Click Discard and start a new recording.
-
Provide a name for the recording (maximum 64 characters) and click Save. The discovered URIs, cookies, and APIs from the recorded business logic sequence are included in subsequent scans, enhancing scan coverage.
Alternatively, click Discard at any time during the recording to cancel.
-
Click OK.
|
|
The Session Status shows if the session is valid. If expired, you are prompted to log in again when you perform scan. You can modify the session timeout at any time, and the latest timeout value updates all recordings based on the cookies or session details of the most recent recording. |
Downloading Discovered Network Endpoints
Select a recording and click Download Discovered Network Endpoints to download a swagger-specification.json file containing detected endpoints.
Deleting a recording
Select a recording you want to delete and click Delete.