From 6354cb33870481311a453a525071991128d8d15f Mon Sep 17 00:00:00 2001 From: Anso Date: Sat, 16 May 2026 20:01:38 -0400 Subject: [PATCH] fix(security-ui): expose Community-tier scan surfaces per PR #930 (#1070) PR #930 opened the backend security routes to Community admin but left several frontend isPaid gates in place, so the matching UI surfaces stayed hidden from Community even though the API would accept the request. This brings the UI in line with the backend matrix. Flipped: - ResourcesView Scan history button (was trivy.available && isPaid) - ResourcesView Full scan (vulnerabilities + secrets) menu item - ResourcesView VulnerabilityScanSheet canCompare - ResourcesView VulnerabilityScanSheet canManageSuppressions (now isAdmin) - EditorView stack-level Scan config button (canScan) - SecurityHistoryView primaryAction (Compare) - SecurityHistoryView VulnerabilityScanSheet canManageSuppressions Unchanged on purpose (still paid, matching backend gates): - canGenerateSbom (SBOM endpoint requirePaid) - SARIF download in the drawer overflow - Scan Policies block in Settings - Trivy auto-update toggle (requireAdmiral) Test: inverted the SecurityHistoryView.test.tsx assertion that locked in the now-incorrect "hides Compare on Community" behavior. --- .../src/components/EditorLayout/EditorView.tsx | 2 +- frontend/src/components/ResourcesView.tsx | 18 ++++++++---------- .../src/components/SecurityHistoryView.tsx | 6 +++--- .../__tests__/SecurityHistoryView.test.tsx | 4 ++-- 4 files changed, 14 insertions(+), 16 deletions(-) diff --git a/frontend/src/components/EditorLayout/EditorView.tsx b/frontend/src/components/EditorLayout/EditorView.tsx index fc79a613..4e558645 100644 --- a/frontend/src/components/EditorLayout/EditorView.tsx +++ b/frontend/src/components/EditorLayout/EditorView.tsx @@ -399,7 +399,7 @@ export function EditorView({ {(() => { const canRollback = isPaid && backupInfo.exists; - const canScan = trivy.available && isAdmin && isPaid; + const canScan = trivy.available && isAdmin; const hasOverflowExtras = canRollback || canScan; return ( diff --git a/frontend/src/components/ResourcesView.tsx b/frontend/src/components/ResourcesView.tsx index 73936095..5f930a64 100644 --- a/frontend/src/components/ResourcesView.tsx +++ b/frontend/src/components/ResourcesView.tsx @@ -732,7 +732,7 @@ export default function ResourcesView() { - {trivy.available && isPaid && ( + {trivy.available && (