From 865884fd7a8b06f8a84790bfaf5d3d530d67d109 Mon Sep 17 00:00:00 2001 From: Olivier Cervello Date: Tue, 21 Jul 2026 16:31:47 +0200 Subject: [PATCH] Add HTTP response Status Code to CSV output MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit security_headers.collect_http_headers already performs the request but discarded the response status on success. Capture it (and the error code on HTTPError) into the collected headers as "Response Code", and add a "Status Code" column to Requests.csv so the real HTTP code is available in machine-readable output — not just "Successful" / an error state. Co-Authored-By: Claude Opus 4.8 --- Python/modules/reporting.py | 7 +++++-- Python/modules/security_headers.py | 13 +++++++++++-- 2 files changed, 16 insertions(+), 4 deletions(-) diff --git a/Python/modules/reporting.py b/Python/modules/reporting.py index 6c105b95..32289c46 100644 --- a/Python/modules/reporting.py +++ b/Python/modules/reporting.py @@ -114,7 +114,7 @@ def sort_data_and_write(cli_parsed, data): web_index_head = create_web_index_head(cli_parsed.date, cli_parsed.time) table_head = create_table_head() counter = 1 - csv_request_data = "Protocol,Port,Domain,URL,Resolved,Request Status,Title,Category,Default Creds,Screenshot Path, Source Path" + csv_request_data = "Protocol,Port,Domain,URL,Resolved,Request Status,Status Code,Title,Category,Default Creds,Screenshot Path, Source Path" # Generate and write json log of requests for json_request in data: @@ -151,7 +151,10 @@ def sort_data_and_write(cli_parsed, data): csv_request_data += "Successful," else: csv_request_data += json_request._error_state + "," - + + # CSV - STATUS CODE (HTTP response code captured in the collected headers) + csv_request_data += str(json_request.http_headers.get('Response Code', '')) + "," + # CSV - TITLE try: # get attribute safely diff --git a/Python/modules/security_headers.py b/Python/modules/security_headers.py index 98ab43a8..533ac840 100644 --- a/Python/modules/security_headers.py +++ b/Python/modules/security_headers.py @@ -64,16 +64,25 @@ def collect_http_headers(url: str, timeout: int = 10, user_agent: str = None, pr headers = {} for header_name, header_value in response.headers.items(): headers[header_name] = header_value - + + # Capture the HTTP response status code so it can be surfaced in the + # report headers section and the CSV (see issue #141). + status_code = getattr(response, 'status', None) + if status_code is None: + status_code = response.getcode() + if status_code is not None: + headers['Response Code'] = str(status_code) + response.close() return headers, None - + except urllib.error.HTTPError as e: # Still try to get headers from error response if e.headers: headers = {} for header_name, header_value in e.headers.items(): headers[header_name] = header_value + headers['Response Code'] = str(e.code) return headers, f"HTTP {e.code} {e.reason}" return None, f"HTTP Error {e.code}: {e.reason}"