mirror of
https://github.com/Studio-Saelix/sencho.git
synced 2026-08-26 02:06:49 +00:00
fix(security): signal when scan comparison is truncated (#658)
Compare endpoint loads up to 1000 findings per scan. When a scan exceeds this cap, the response now includes truncated=true and row_limit, and the comparison sheet surfaces a banner so users understand the diff may be incomplete. Also exposes total_vulnerabilities on scanA/scanB for UI use and logs a warning when truncation occurs.
This commit is contained in:
@@ -150,6 +150,27 @@ describe('ScanComparisonSheet', () => {
|
||||
);
|
||||
});
|
||||
|
||||
it('renders the truncation banner when the response flags truncated', async () => {
|
||||
mockedFetch.mockResolvedValueOnce(
|
||||
jsonResponse(200, result({ truncated: true, row_limit: 1000 })),
|
||||
);
|
||||
|
||||
render(<ScanComparisonSheet baselineScanId={1} currentScanId={2} onClose={() => {}} />);
|
||||
|
||||
await waitFor(() =>
|
||||
expect(screen.getByText(/first 1000 findings per scan/i)).toBeInTheDocument(),
|
||||
);
|
||||
});
|
||||
|
||||
it('hides the truncation banner when truncated is false', async () => {
|
||||
mockedFetch.mockResolvedValueOnce(jsonResponse(200, result({ truncated: false })));
|
||||
|
||||
render(<ScanComparisonSheet baselineScanId={1} currentScanId={2} onClose={() => {}} />);
|
||||
|
||||
await waitFor(() => expect(screen.getByText(/Baseline/i)).toBeInTheDocument());
|
||||
expect(screen.queryByText(/findings per scan/i)).toBeNull();
|
||||
});
|
||||
|
||||
it('reloads when the scan ids change', async () => {
|
||||
mockedFetch.mockResolvedValue(jsonResponse(200, result()));
|
||||
|
||||
|
||||
Reference in New Issue
Block a user