Skip to content

Add API Fuzzing to security dashboard and vulnerabilities details page

- requested to merge 271529-add-api-fuzzing-category into master

What does this MR do?

Implements adding api_fuzzing to the security dashboard dropdown

#271529 (closed)

Also implements adding API fuzz testing fields to the vulnerabilities details page

#271535 (closed)

Notes on differences with screenshots

  • I spoke with @cam.x and the grey areas were changed to match the existing black code areas.

  • The diffing logic/highlighting will be implemented in a different issue. #271536 (closed)

Screenshots (strongly suggested)

Screen_Shot_2020-11-04_at_12.27.23_AM

Screen_Shot_2020-11-08_at_5.43.09_PM

Does this MR meet the acceptance criteria?

Conformity

Availability and Testing

Security

If this MR contains changes to processing or storing of credentials or tokens, authorization and authentication methods and other items described in the security review guidelines:

  • Label as security and @ mention @gitlab-com/gl-security/appsec
  • The MR includes necessary changes to maintain consistency between UI, API, email, or other methods
  • Security reports checked/validated by a reviewer from the AppSec team

Related to #271529 (closed)

Edited by Neil McCorrison

Merge request reports