WP-20/21: contract and failing tests for vulnerability management
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
36
frontend/e2e/vulnerabilities.spec.ts
Normal file
36
frontend/e2e/vulnerabilities.spec.ts
Normal file
@ -0,0 +1,36 @@
|
||||
import { test, expect } from '@playwright/test'
|
||||
|
||||
test('admin runs a scan, filters findings and acknowledges one', async ({ page }) => {
|
||||
await page.goto('/login')
|
||||
await page.getByLabel('Email').fill('admin@example.com')
|
||||
await page.getByLabel('Password').fill('admin-password-123')
|
||||
await page.getByRole('button', { name: 'Sign in' }).click()
|
||||
await page.getByRole('link', { name: 'Vulnerabilities' }).click()
|
||||
|
||||
await page.getByRole('button', { name: 'Scan now' }).click()
|
||||
await expect(page.getByTestId('count-critical')).not.toHaveText('0', { timeout: 20_000 })
|
||||
await expect(page.getByRole('row', { name: /CVE-2023-45853/ })).toBeVisible()
|
||||
|
||||
await page.getByLabel('Minimum severity').selectOption('critical')
|
||||
await expect(page.getByRole('row', { name: /CVE-2011-3374/ })).toHaveCount(0)
|
||||
await page.getByLabel('Minimum severity').selectOption('low')
|
||||
await expect(page.getByRole('row', { name: /CVE-2011-3374/ })).toBeVisible()
|
||||
|
||||
const row = page.getByRole('row', { name: /CVE-2023-45853/ })
|
||||
await row.getByRole('button', { name: 'Acknowledge' }).click()
|
||||
await expect(row).toContainText('acknowledged')
|
||||
|
||||
await row.getByRole('button', { name: 'Details' }).click()
|
||||
await expect(page.getByRole('dialog')).toContainText('zlib')
|
||||
})
|
||||
|
||||
test('notification threshold can be changed in settings', async ({ page }) => {
|
||||
await page.goto('/login')
|
||||
await page.getByLabel('Email').fill('admin@example.com')
|
||||
await page.getByLabel('Password').fill('admin-password-123')
|
||||
await page.getByRole('button', { name: 'Sign in' }).click()
|
||||
await page.getByRole('link', { name: 'Settings' }).click()
|
||||
await page.getByLabel('Notify from severity').selectOption('medium')
|
||||
await page.getByRole('button', { name: 'Save notifications' }).click()
|
||||
await expect(page.getByRole('status')).toContainText('Notification settings saved')
|
||||
})
|
||||
@ -128,3 +128,38 @@ export interface ClusterOverview {
|
||||
images: string[]
|
||||
fetched_at: string
|
||||
}
|
||||
|
||||
export type Severity = 'critical' | 'high' | 'medium' | 'low' | 'unknown'
|
||||
export type FindingStatus = 'open' | 'acknowledged' | 'fixed'
|
||||
|
||||
export interface Finding {
|
||||
id: string
|
||||
target_kind: 'os' | 'image'
|
||||
target: string
|
||||
cve_id: string
|
||||
severity: Severity
|
||||
package: string
|
||||
installed_version: string
|
||||
fixed_version: string | null
|
||||
title: string
|
||||
url: string
|
||||
status: FindingStatus
|
||||
first_seen: string
|
||||
last_seen: string
|
||||
}
|
||||
|
||||
export interface SeverityCounts {
|
||||
critical: number
|
||||
high: number
|
||||
medium: number
|
||||
low: number
|
||||
unknown: number
|
||||
}
|
||||
|
||||
export interface VulnSummary {
|
||||
total: SeverityCounts
|
||||
os: SeverityCounts
|
||||
images: SeverityCounts
|
||||
last_scan: string | null
|
||||
scanner: string
|
||||
}
|
||||
|
||||
58
frontend/src/components/FindingTable.test.ts
Normal file
58
frontend/src/components/FindingTable.test.ts
Normal file
@ -0,0 +1,58 @@
|
||||
import { mount } from '@vue/test-utils'
|
||||
import FindingTable from './FindingTable.vue'
|
||||
import type { Finding } from '../api/types'
|
||||
|
||||
const f = (over: Partial<Finding>): Finding => ({
|
||||
id: over.cve_id ?? 'x',
|
||||
target_kind: 'os',
|
||||
target: 'os',
|
||||
cve_id: 'CVE-0',
|
||||
severity: 'low',
|
||||
package: 'pkg',
|
||||
installed_version: '1',
|
||||
fixed_version: null,
|
||||
title: 'title',
|
||||
url: 'https://x',
|
||||
status: 'open',
|
||||
first_seen: '2026-09-01T00:00:00Z',
|
||||
last_seen: '2026-09-02T00:00:00Z',
|
||||
...over,
|
||||
})
|
||||
|
||||
const findings = [
|
||||
f({ cve_id: 'CVE-1', severity: 'critical', package: 'zlib1g', fixed_version: '1.3' }),
|
||||
f({
|
||||
cve_id: 'CVE-2',
|
||||
severity: 'high',
|
||||
target_kind: 'image',
|
||||
target: 'gitea/gitea:1.22',
|
||||
status: 'acknowledged',
|
||||
}),
|
||||
]
|
||||
|
||||
describe('FindingTable', () => {
|
||||
it('renders severity, target, fix version and status', () => {
|
||||
const w = mount(FindingTable, { props: { findings, canAct: true } })
|
||||
const rows = w.findAll('tbody tr')
|
||||
expect(rows).toHaveLength(2)
|
||||
expect(rows[0].text()).toContain('critical')
|
||||
expect(rows[0].text()).toContain('1.3')
|
||||
expect(rows[1].text()).toContain('gitea/gitea:1.22')
|
||||
expect(rows[1].text()).toContain('acknowledged')
|
||||
})
|
||||
|
||||
it('emits acknowledge/reopen and opens details', async () => {
|
||||
const w = mount(FindingTable, { props: { findings, canAct: true } })
|
||||
await w.findAll('button[name=ack]')[0].trigger('click')
|
||||
expect(w.emitted('status')![0]).toEqual([findings[0], 'acknowledged'])
|
||||
await w.findAll('button[name=ack]')[1].trigger('click')
|
||||
expect(w.emitted('status')![1]).toEqual([findings[1], 'open'])
|
||||
await w.findAll('button[name=details]')[0].trigger('click')
|
||||
expect(w.emitted('select')![0][0]).toEqual(findings[0])
|
||||
})
|
||||
|
||||
it('hides actions for viewers', () => {
|
||||
const w = mount(FindingTable, { props: { findings, canAct: false } })
|
||||
expect(w.findAll('button[name=ack]')).toHaveLength(0)
|
||||
})
|
||||
})
|
||||
Reference in New Issue
Block a user