Skip to content

Fix: broken event links - #966

Open
Ph4t3 wants to merge 4 commits into
mainfrom
fix/broken-event-links
Open

Ph4t3 wants to merge 4 commits into
mainfrom
fix/broken-event-links

Conversation

@Ph4t3

@Ph4t3 Ph4t3 commented Oct 7, 2026 •

Copy link
Copy Markdown
Collaborator

Closes l3montree-dev/devguard#3072

Events linking to the individual risk pages they were triggered in only worked for dependency-risks and code-risks pages, as only those were checked for in the route in VulnEventItem.tsx
The way the condition was set, dependency-risk related events worked properly, and all other events got routed to code-risks/vulnId, which worked for code-risks pages, but not for license-risks, security-advisories or compliance-postures.

Because the code-risks/[vulnId]/page.tsx had it's error check after the (isLoading || !vuln) and it's loading skeleton return, !vuln always got triggered first, resulting in all license-risk, advisory and compliance-posture events linking to a code-risks/ URL that then silently 404d and infinitely showed the loading skeleton, as the vulnId for either of these 3 risks cannot be found as a vulnId for a code-risk.

Compliance-posture pages are the only pages not using vulnId for their [vulnId] slug, but instead use framework_control_id for their routes, so the backend needs to supply this here as well to construct the route correctly.

This was implemented using vulnerabilityName now containing the framework_control_id for compliance-postures, the same way dependency-risks already gets the CVE name, while all other risks contain null.

The generated vulnType was used to accurately map the backend names to their frontend counterparts and catch errors like this at compile time going forward.

This PR has to be merged in sync with this backend PR: l3montree-dev/devguard#3173

Ph4t3 added 2 commits October 6, 2026 15:34
…nside vulnerabilityName for route to compliance-postures, check error before loading in code-risks to get rid of silent 404 skeleton loading state
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Overview event stream link to ever loading code risk page (404, but no error given to user)

1 participant