Skip to content

fix: harden CrowdSec editor, responses and hub URL checks; deterministic CrowdSec specs - #1535

Merged
Wikid82 merged 22 commits into
developmentfrom
fix/crowdsec-hub-url-and-editor-hardening
Oct 10, 2026
Merged

Wikid82 merged 22 commits into
developmentfrom
fix/crowdsec-hub-url-and-editor-hardening

Conversation

@Wikid82

@Wikid82 Wikid82 commented Oct 10, 2026 •

Copy link
Copy Markdown
Owner

Summary

Follow-ups to #1525, delivered as one PR: CrowdSec editor and response hardening, a stricter hub URL check, the Playwright cleanup from #1526, and the real bugs that cleanup uncovered. Plan: docs/plans/current_spec.md; QA report: docs/reports/qa_report.md.

Closes #1528, closes #1479, closes #1481, closes #1526, closes #1530, closes #1531

Tests removed on purpose

Old Playwright cases that asserted UI that does not exist (decisions search/filter/refresh/back-navigation, diagnostic status badges, "LAPI ready" text) or depended on a feature flag that is off by default (real-backend enrollment API cases) were replaced by stubbed equivalents. The "tenant is required" case was removed because tenant is optional.

Testing

  • Backend: coverage 91.0% statements / 90.1% lines; full golangci-lint config clean (backend and agent); go vet clean.
  • Frontend: coverage 91.46% lines; type-check, lint, build pass.
  • Patch coverage locally 98.9% (one unreachable Close() error branch).
  • E2E: the nine CrowdSec security specs pass under --project=security-tests (179 tests, no fixme).
  • Security checks: govulncheck, Trivy (dependency files), Semgrep and all pre-commit hooks clean. CodeQL and the image scan run in CI.

Wikid82 added 22 commits October 9, 2026 20:51
Tighten which generated files the CrowdSec configuration editor will list, open and save, and add tests covering the new behavior.
CrowdSec API responses and UI messages now identify backups by name only,
with a location hint in the UI. Detail stays in the server log.
… changes

Enable the end-to-end checks added earlier and describe the editor, backup
naming and hub address behavior in the user docs.
Rewrite the dashboard and banned IPs specs against stubbed CrowdSec
endpoints so every assertion runs on known data instead of tolerating
whatever the engine-less E2E container returns. Dashboard covers tabs,
summary cards, charts, active decisions sorting, alerts paging, time
range selection, refresh and export, including empty and error states.
Banned IPs covers listing, the disabled and error states, and the exact
ban and unban requests. Non-existent search, filter, refresh and
navigation controls are removed rather than skipped.

Extend the shared stub helper with security status mode, dashboard,
alerts, export and ban endpoints plus request recording.

Point the two known fixme cases in crowdsec-config.spec.ts at #1530,
where the findings from that spec are now tracked.
Rewrite the console enrollment spec against a stubbed enrollment API so it
no longer depends on the feature flag or on a CrowdSec engine. Covers each
enrollment state (not enrolled, enrolling, pending acceptance, enrolled,
failed) with its timestamps, heartbeat and masked last error, validation,
the exact enroll, rotate, retry and re-enroll request payloads, refreshed
status and server error outcomes, clearing the local state, and gating on
local API readiness.

The old real-backend contract checks for diagnostics and heartbeat are
dropped here: diagnostics belongs to the diagnostics spec, and the UI
reads heartbeat from the console status.
Import a known configuration before each diagnostics, export and file test and
assert the exact responses. Replace the two diagnostics UI checks, which looked for
text the page never renders, with stubbed Security page running and stopped states.
Add a fixme for the export being gzipped twice when the client accepts compression.
Retitle existing fixmes to reference #1530 and #1531.
The export is already a .tar.gz, so it is excluded from the router-wide
compression. Clients that accept gzip now receive one valid archive.
Add the missing CrowdSec config and whitelist keys to all five locales,
use real keys for aria-labels instead of a dead fallback, give the
dashboard time-range group a string label, and only mask token-like
strings in console enrollment errors. A test now checks that every
static key resolves and that locales stay in parity.
…back

The backend treats the tenant as optional and requires the agent name, so
the form no longer demands a tenant and the agent name label drops its
optional marker. The agent name and tenant now initialize from the
enrolled status without overwriting user edits, and clearing the
enrollment state reports failures through a toast.
@github-advanced-security

Copy link
Copy Markdown
Contributor

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@github-actions

Copy link
Copy Markdown
Contributor

✅ Supply Chain Verification Results

✅ PASSED

📦 SBOM Summary

  • Components: 1870

🔍 Vulnerability Scan

Severity Count
🔴 Critical 0
🟠 High 0
🟡 Medium 0
🟢 Low 0
Total 0

📎 Artifacts

  • SBOM (CycloneDX JSON) and Grype results available in workflow artifacts

Generated by Supply Chain Verification workflow • View Details

@codecov

codecov Bot commented Oct 10, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 96.26168% with 4 lines in your changes missing coverage. Please review.

Files with missing lines Patch % Lines
...d/internal/api/handlers/crowdsec_preset_handler.go 77.77% 2 Missing ⚠️
backend/internal/crowdsec/hub_sync.go 92.85% 1 Missing ⚠️
frontend/src/hooks/useConsoleEnrollment.ts 66.66% 0 Missing and 1 partial ⚠️

📢 Thoughts on this report? Let us know!

@Wikid82
Wikid82 marked this pull request as ready for review October 10, 2026 02:42
@Wikid82
Wikid82 merged commit 6376038 into development Oct 10, 2026
48 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants