Skip to content

Add request/response to standalone vulnerability page

What does this MR do?

It adds both the request and response information to the standalone vulnerability page.

This includes:

  • backend change to include request and response data within API's data
  • frontend changes to display the fields when they are present

How to test this locally

  1. Create a new project
  2. Add this gitlab-ci.yml
  3. Create a dast.json and copy the content from https://gitlab.com/gitlab-org/security-products/dast/-/blob/master/test/end-to-end/expect/test_baseline_api_scan.json into the file
  4. Run pipeline on master

Screenshots

before after
standalone_before standalone_after

Does this MR meet the acceptance criteria?

Conformity

Availability and Testing

Security

If this MR contains changes to processing or storing of credentials or tokens, authorization and authentication methods and other items described in the security review guidelines:

  • Label as security and @ mention @gitlab-com/gl-security/appsec
  • The MR includes necessary changes to maintain consistency between UI, API, email, or other methods
  • Security reports checked/validated by a reviewer from the AppSec team

Related to #217368 (closed)

Edited by David Pisek

Merge request reports

Loading