Show scan profile name on disabled rows and surface mutation errors

What does this MR do and why?

Improves legibility and error handling in the security scan profile UI across three areas.

First, when a single-profile scanner row is marked DISABLED in the bulk drawer, the "Profile" cell now shows the profile name instead of "No profile applied", so users can see which profile would be re-enabled if they clicked Apply default profile to all.

Second, the project-level scan profile configuration page applies the same fix: rows with an available but unapplied profile now show the profile name.

Third, the bulk drawer's attach and detach mutations now check the errors array in the GraphQL response, not just network failures. When a semantic error occurs (for example, detaching a profile that was not attached), the drawer shows an error alert and skips the success toast and local status update. Server-side errors are forwarded to Sentry through the alert's error field.

The bulk drawer's attachProfile and detachProfile share a new showMutationError(message, error) helper, so the .then() graphql-errors branch and the .catch() network-failure branch surface the same user-facing string.

Files touched: bulk_scanner_profile_configuration.vue, bulk_scanners_update_drawer.vue, and scan_profile_configuration.vue, plus their specs.

References

Screenshots or screen recordings

Before After
bulk drawer
project-level scan profile configuration page
bulk error msg
apply error msg

How to set up and validate locally

  1. Navigate to a project's security configuration page under an EE license.
  2. Find a scanner row with an available profile but no attached profile. Confirm the "Profile" column shows the recommended profile name (for example, "Secret Detection - Standard"), not "No profile applied".
  3. From the group's Security inventory, select two or more items and open the bulk update drawer. On a single-profile row, click Disable for all and confirm. Verify the "Profile" column now shows the profile name, the scan-type icon is red, and the Disable for all button is gone.
  4. To test mutation error handling, open the browser's network tab, click Disable for all, and in devtools override the response so securityScanProfileDetach.errors contains a string. Confirm a danger alert appears in the drawer with the generic disabling message and no success toast is shown. (Unit tests cover this branch directly.)

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Edited by Chen Charnolevsky

Merge request reports

Loading
Loading