Repository navigation
fix: harden CrowdSec editor, responses and hub URL checks; deterministic CrowdSec specs - #1535
Merged
Merged
Conversation
Tighten which generated files the CrowdSec configuration editor will list, open and save, and add tests covering the new behavior.
CrowdSec API responses and UI messages now identify backups by name only, with a location hint in the UI. Detail stays in the server log.
… changes Enable the end-to-end checks added earlier and describe the editor, backup naming and hub address behavior in the user docs.
Rewrite the dashboard and banned IPs specs against stubbed CrowdSec endpoints so every assertion runs on known data instead of tolerating whatever the engine-less E2E container returns. Dashboard covers tabs, summary cards, charts, active decisions sorting, alerts paging, time range selection, refresh and export, including empty and error states. Banned IPs covers listing, the disabled and error states, and the exact ban and unban requests. Non-existent search, filter, refresh and navigation controls are removed rather than skipped. Extend the shared stub helper with security status mode, dashboard, alerts, export and ban endpoints plus request recording. Point the two known fixme cases in crowdsec-config.spec.ts at #1530, where the findings from that spec are now tracked.
Rewrite the console enrollment spec against a stubbed enrollment API so it no longer depends on the feature flag or on a CrowdSec engine. Covers each enrollment state (not enrolled, enrolling, pending acceptance, enrolled, failed) with its timestamps, heartbeat and masked last error, validation, the exact enroll, rotate, retry and re-enroll request payloads, refreshed status and server error outcomes, clearing the local state, and gating on local API readiness. The old real-backend contract checks for diagnostics and heartbeat are dropped here: diagnostics belongs to the diagnostics spec, and the UI reads heartbeat from the console status.
Import a known configuration before each diagnostics, export and file test and assert the exact responses. Replace the two diagnostics UI checks, which looked for text the page never renders, with stubbed Security page running and stopped states. Add a fixme for the export being gzipped twice when the client accepts compression. Retitle existing fixmes to reference #1530 and #1531.
The export is already a .tar.gz, so it is excluded from the router-wide compression. Clients that accept gzip now receive one valid archive.
Add the missing CrowdSec config and whitelist keys to all five locales, use real keys for aria-labels instead of a dead fallback, give the dashboard time-range group a string label, and only mask token-like strings in console enrollment errors. A test now checks that every static key resolves and that locales stay in parity.
…back The backend treats the tenant as optional and requires the agent name, so the form no longer demands a tenant and the agent name label drops its optional marker. The agent name and tenant now initialize from the enrolled status without overwriting user edits, and clearing the enrollment state reports failures through a toast.
Contributor
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
Contributor
✅ Supply Chain Verification Results✅ PASSED 📦 SBOM Summary
🔍 Vulnerability Scan
📎 Artifacts
Generated by Supply Chain Verification workflow • View Details |
Codecov Report❌ Patch coverage is 📢 Thoughts on this report? Let us know! |
Wikid82
marked this pull request as ready for review
October 10, 2026 02:42
This was referenced Oct 10, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Follow-ups to #1525, delivered as one PR: CrowdSec editor and response hardening, a stricter hub URL check, the Playwright cleanup from #1526, and the real bugs that cleanup uncovered. Plan:
docs/plans/current_spec.md; QA report:docs/reports/qa_report.md.Closes #1528, closes #1479, closes #1481, closes #1526, closes #1530, closes #1531
tests/utils/crowdsec-stubs.ts), no tolerant patterns left.codecov/patchshould appear once, near the end of the run. If it misbehaves, revert693d7a22and513440f5ondevelopment.Tests removed on purpose
Old Playwright cases that asserted UI that does not exist (decisions search/filter/refresh/back-navigation, diagnostic status badges, "LAPI ready" text) or depended on a feature flag that is off by default (real-backend enrollment API cases) were replaced by stubbed equivalents. The "tenant is required" case was removed because tenant is optional.
Testing
Close()error branch).--project=security-tests(179 tests, no fixme).