Repository navigation
Conversation
…nside vulnerabilityName for route to compliance-postures, check error before loading in code-risks to get rid of silent 404 skeleton loading state
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes l3montree-dev/devguard#3072
Events linking to the individual risk pages they were triggered in only worked for dependency-risks and code-risks pages, as only those were checked for in the route in
VulnEventItem.tsxThe way the condition was set, dependency-risk related events worked properly, and all other events got routed to
code-risks/vulnId, which worked for code-risks pages, but not for license-risks, security-advisories or compliance-postures.Because the
code-risks/[vulnId]/page.tsxhad it's error check after the(isLoading || !vuln)and it's loading skeleton return,!vulnalways got triggered first, resulting in all license-risk, advisory and compliance-posture events linking to acode-risks/URL that then silently 404d and infinitely showed the loading skeleton, as the vulnId for either of these 3 risks cannot be found as a vulnId for a code-risk.Compliance-posture pages are the only pages not using vulnId for their [vulnId] slug, but instead use
framework_control_idfor their routes, so the backend needs to supply this here as well to construct the route correctly.This was implemented using
vulnerabilityNamenow containing theframework_control_idfor compliance-postures, the same way dependency-risks already gets the CVE name, while all other risks contain null.The generated vulnType was used to accurately map the backend names to their frontend counterparts and catch errors like this at compile time going forward.
This PR has to be merged in sync with this backend PR: l3montree-dev/devguard#3173